YOUR FEEDBACK
Bill Miller wrote: Good article. Data Services is a great place to get value from SOA, and a great...
AJAXWorld RIA Conference
Early Bird Savings Expire Friday Register Today and SAVE !..

2008 East
DIAMOND SPONSOR:
Data Direct
Frontiers in Data Access: The Coming Wave in Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
Intel
Virtualization – Path to Predictive Enterprise
Green Hills
IT Security in a Hostile World
JBoss / freedom oss
Practical SOA Approach
GOLD SPONSORS:
Software AG
The Art & Science of SOA: How Governance Enables Adoption
PlateSpin
Effective Planning for Virtual Infrastructure Growth
Fujitsu
Automated Business Process Discovery & Virtualization Service
Ceedo
Workspace Virtualization
Click For 2007 West
Event Webcasts

2008 East
PLATINUM SPONSORS:
Appcelerator
Think Fast: Accelerate AJAX Development with Appcelerator
GOLD SPONSORS:
DreamFace Interactive
The Ultimate Framework for Creating Personalized Web 2.0 Mashups
ICEsoft
AJAX and Social Computing for the Enterprise
Kaazing
Enterprise Comet: Real–Time, Real–Time, or Real–Time Web 2.0?
Nexaweb
Now Playing: Desktop Apps in the Browser!
Sun
jMaki as an AJAX Mashup Framework
POWER PANELS:
The Business Value
of RIAs
What Lies Beyond AJAX?
KEYNOTES:
Douglas Crockford
Can We Fix the Web?
Anthony Franco
2008: The Year of the RIA
Click For 2007 Event Webcasts

SYS-CON.TV
TOP THREE LINKS YOU MUST CLICK ON


Watch Your Security Hole
Watch Your Security Hole

Anyone who has recently been on the job hunting circuit, looking for a position as a developer, knows that employers are getting rather picky. With the oversupply of IT professionals, recruiters are not just looking for good people, they are looking for good people with an exact skill set to match their requirements. As such, the chances of getting the position you desire is not as guaranteed as it was back in the boom times four years ago. Besides having good looks and luck, one of the ways that you can get around this dilemma is to maintain a diverse set of skills on your résumé and hope that some combination will get you the job.

One of the traditional "must-have" items on your résumé used to be working knowledge of relational database systems (and associated APIs) or application servers. Job requisitions would be combinations of Java/Oracle, WebLogic Server/J2EE/Sybase, etc. The trend now, especially in the new millennium where the Internet can sometimes appear as a vast wasteland swarming with viruses, worms, and other types of low life, is that security issues have taken center stage - both in and out of cyberspace.

For example, a leading IT consulting company has recently upgraded their methodology to include security-related issues and design. What makes this particularly interesting is that this methodology addresses security-related issues during all phases of the project life cycle, starting with the envisioning phase and on through to the operational services phase. In another case, the Microsoft Solutions Framework includes security in a number of different phases in their process model, starting early in the planning phase. As is evident in these examples, security issues are no longer an afterthought and need to be addressed throughout application and system development, and rightly so.

Now, what this means for the average Joe Developer is this: you should start thinking more about further developing your knowledge and skills related to IT security and make sure your résumé reflects whatever experience you do have. To start, you will need some working knowledge regarding basic security concepts, including encryption, authentication, and authorization. That is just the basics! When you move into the Web services space, there are other security-related specifications that you should be aware of, including WS-Security and SAML. Therefore, if you haven't paid much attention to your security-related skill sets, or if you think that it's only for the security specialist or guru, it's time to think again.

To help you begin to sort through all this stuff, this month we will focus on some of the security issues and solutions that you may come across as a WebLogic developer. You will also get up to speed on the new Enterprise Security Initiative, announced by BEA, which will introduce a number of security management services to the BEA WebLogic Server platform, including single sign-on and other advanced security features.

Finally, if you just happen to be in San Francisco during the May 24-27 time frame, come and visit the Ninth Annual BEA eWorld Technology Conference at the Moscone West Convention Center in town. The conference promises to provide you with the latest on what is happening at BEA, and will be jam-packed with new and exciting hands-on sessions and a variety of keynote speakers. You will also find an exhibit floor full of BEA partners and vendors with plenty of giveaways to help fill up your "techy" bag. For more information and to sign up for the event, check the BEA Web site at www.bea.com. I look forward to meeting all of you there!

About Joe Mitchko
Joe Mitchko is the editor-in-chief of WLDJ and a senior technical specialist for a leading consulting services company.

BEA WEBLOGIC LATEST STORIES
Since its emergence, Web Service technology has gone a long way towards perfecting itself and finding its right application in the real world. With the maturity of the specifications, Web Service technology, with its power of interoperability, is now the major enabling technology of SO...
Join Scott Guthrie as he discusses Microsoft’s commitment to web standards development, Rich Internet Applications and how Microsoft is contributing to help move the web forward. Join Adobe’s Kevin Lynch as he demonstrates how Flash and HTML come together to make the most engaging,...
Virtualization has become a critical part of Enterprise IT strategy. Why and how has it become one of the most important change agents in our industry? To answer these questions I had the good fortune recently to be able to speak to a select group of top IT industry executives who join...
Watching VMware stock and its market cap spike since it IPO'd must have had Red Hat positively pea green with envyWatching VMware stock and its market cap spike since it IPO'd must have had Red Hat positively pea green with envy - so green in fact that it's gonna try taking VMware on b...
A standard from OASIS called Web Services for Remote Portlets (WSRP) is used so portlets can be decoupled from a portal. In part one (JDJ, Volume. 13, issue 3) of this article, we introduced the relevant standards and specifications and then demonstrated WSRP's capabilities by consumin...
SYS-CON's upcoming '3rd International Virtualization Conference & Expo' faculty includes such distinguished speakers as: Al Aghili (Managed Methods), Alan Chhabra (Egenera), Andi Mann (Enterprise Management Associates), Andrew Conte (APC), Andy Astor (EnterpriseDB), Ariel Cohen (Xsigo ...
SUBSCRIBE TO THE WORLD'S MOST POWERFUL NEWSLETTERS
SUBSCRIBE TO OUR RSS FEEDS & GET YOUR SYS-CON NEWS LIVE!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON FEATURED WHITEPAPERS

ADS BY GOOGLE
BREAKING NEWS FROM THE WIRES

Autodesk, Inc. (NASDAQ:ADSK) today announced that its Autodesk LocationLogic platfo...