Author Archives: Application Security

Enterprise API Management for Mobile Part 2 – Don’t Trust. And Verify

In the previous post we looked at some of the policy zones that an Enterprise API Management has in Mobile security, including: 1. External security policy: for the Mobile device -> API Management Layer message exchanges 2. Internal security policy: … Read more >

The post Enterprise API Management for Mobile Part 2 – Don’t Trust. And Verify appeared first on Application Security.

Read more >

Big Data, IoT, API …….Newer technologies protected by older security.

Now-a-days every single CIO, CTO, or business executive that I speak to is captivated by these three new technologies: Big Data, API management and IoTs (Internet of Things). Every single organizational executive that I speak with confirms that they either … Read more >

The post Big Data, IoT, API …….Newer technologies protected by older security. appeared first on Application Security.

Read more >

Be Your Own Broker: An Enterprise Perspective using API Management

Kin Lane has started tracking what he calls API Brokers over at API Evangelist. This quote illustrates the promise of API brokerage: I envision other new API brokers emerging, in niche areas like images, video or messaging. Imagine if you could … Read more >

The post Be Your Own Broker: An Enterprise Perspective using API Management appeared first on Application Security.

Read more >

Cloud-Aware Tokenization: Helping to Build PCI-Compliant Applications in the Cloud

Last year the Open Data Center Alliance published an excellent whitepaper that defined the concept of “cloud-aware” applications.  The ODCA paper sets forth the following recommendations: Everything is a Service Use RESTful APIs Separate Compute and Persistence Design for Failure … Read more >

The post Cloud-Aware Tokenization: Helping to Build PCI-Compliant Applications in the Cloud appeared first on Application Security.

Read more >

From ESBs to API Portals: an Evolutionary Journey Part 4

The  continuing transformation of the IT industry around the externalization of  service components constitutes an exercise in abstraction.  The transformation assumes that any IT  application can be recursively decomposed into constituent services.  An application that has been re-architected  or engineered … Read more >

The post From ESBs to API Portals: an Evolutionary Journey Part 4 appeared first on Application Security.

Read more >

Betwixt and Between – Service Gateway for Enterprise Mobile Applications

Over the next several posts, I will explore some of the core patterns for Service Gateways that provide access to Enterprise Mobile Applications that need to leverage enterprise apps and data. Before I go there – a word about risk. … Read more >

The post Betwixt and Between – Service Gateway for Enterprise Mobile Applications appeared first on Application Security.

Read more >

Mobile Middleware for the Enterprise: API Security Considerations

A few weeks ago I blogged about different Mobile Middleware usage models for enterprise.  Continuing that thread, this post will drill down into API security considerations for enterprise mobile apps. Mobile applications are typically intended for use outside of the … Read more >

The post Mobile Middleware for the Enterprise: API Security Considerations appeared first on Application Security.

Read more >

From ESBs to API Portals: an Evolutionary Journey Part 3

In this article series we build the case for API portals, out of which the Intel® Expressway Service Gateway and the Intel® API Manager, powered by Mashery are representative examples, as the contemporary manifestations of the SOA movement that transformed IT in the … Read more >

The post From ESBs to API Portals: an Evolutionary Journey Part 3 appeared first on Application Security.

Read more >