ISO/IEC 17998:2012
(Main)Information technology — SOA Governance Framework
Information technology — SOA Governance Framework
ISO/IEC 17998:2012 describes a framework that provides context and definitions to enable organizations to understand and deploy service-oriented architecture (SOA) governance. ISO/IEC 17998:2012 defines: SOA Governance, including its relationship between Business, IT, and EA governance; this assists organizations in understanding the impact that the introduction of SOA into an organization has on governance; an SOA Governance Reference Model (SGRM) and its constituent parts, which assists organizations in specifying their appropriate governance regimes; and capturing best practice as a basis for a common approach; the SOA Governance Vitality Method (SGVM) which assists organizations in customizing the SGRM and realizing their SOA Governance Regimen. ISO/IEC 17998:2012 is not intended to be used as provided; it is intended to be customized to create appropriate SOA governance for the organization. Many of the lists are non-normative and exemplary and intended to be filtered and as input to the customization process. ISO/IEC 17998:2012 does not include an explanation of the fundamentals and value of SOA, which is important for being able to understand and apply SOA governance. It lists some of the many other specifications and books that are available on SOA basics.
Technologies de l'information — Cadre de gouvernance SOA
General Information
Relations
Standards Content (Sample)
INTERNATIONAL ISO/IEC
STANDARD 17998
First edition
2012-09-01
Information technology — SOA
Governance Framework
Technologies de l'information — Cadre de gouvernance SOA
Reference number
©
ISO/IEC 2012
© ISO/IEC 2012
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means,
electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or
ISO's member body in the country of the requester.
ISO copyright office
Case postale 56 CH-1211 Geneva 20
Tel. + 41 22 749 01 11
Fax + 41 22 749 09 47
E-mail copyright@iso.org
Web www.iso.org
Published in Switzerland
ii © ISO/IEC 2012 – All rights reserved
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members of
ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of information
technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1.
International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 2.
The main task of the joint technical committee is to prepare International Standards. Draft International
Standards adopted by the joint technical committee are circulated to national bodies for voting. Publication as
an International Standard requires approval by at least 75 % of the national bodies casting a vote.
Attention is drawn to the possibility that some of the elements of this document may be the subject of patent
rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights.
ISO/IEC 17998 was prepared by The Open Group and was adopted, under the PAS procedure, by Joint
Technical Committee ISO/IEC JTC 1, Information technology, in parallel with its approval by national bodies of
ISO and IEC.
© ISO/IEC 2012 – All rights reserved iii
Technical Standard
SOA Governance Framework
The Open Group hereby authorizes you to copy this document for non-commercial use within your organization only. In
consideration of this authorization, you agree that any copy of this document which you make shall retain all copyright
and other proprietary notices contained herein.
This document may contain other proprietary notices and copyright information.
Nothing contained herein shall be construed as conferring by implication, estoppel, or otherwise any license or right
under any patent or trademark of The Open Group or any third party. Except as expressly provided above, nothing
contained herein shall be construed as conferring any license or right under any copyright of The Open Group.
Note that any product, process, or technology in this document may be the subject of other intellectual property rights
reserved by The Open Group, and may not be licensed hereunder.
This document is provided "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED,
INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR
A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. Some jurisdictions do not allow the exclusion of implied
warranties, so the above exclusion may not apply to you.
Any publication of The Open Group may include technical inaccuracies or typographical errors. Changes may be
periodically made to these publications; these changes will be incorporated in new editions of these publications. The
Open Group may make improvements and/or changes in the products and/or the programs described in these
publications at any time without notice.
Should any viewer of this document respond with information including feedback data, such as questions, comments,
suggestions, or the like regarding the content of this document, such information shall be deemed to be non-confidential
and The Open Group shall have no obligation of any kind with respect to such information and shall be free to
reproduce, use, disclose and distribute the information to others without limitation. Further, The Open Group shall be
free to use any ideas, concepts, know-how, or techniques contained in such information for any purpose whatsoever
including but not limited to developing, manufacturing, and marketing products incorporating such information.
Technical Standard
SOA Governance Framework
ISBN: 1-931624-82-8
Document Number: C093
Published by The Open Group, August 2009.
Comments relating to the material contained in this document may be submitted to:
The Open Group, Thames Tower, 37-45 Station Road, Reading, Berkshire, RG1 1LX, United Kingdom
or by electronic mail to: ogspecs@opengroup.org
ii Technical Standard (2009)
© ISO/IEC 2012 – All rights reserved
Contents
1 Introduction.1
1.1 Objective.1
1.2 Overview.1
1.3 Conformance.2
1.4 Terminology.3
1.5 Future Directions .4
2 Background .6
2.1 SOA Challenges and Goals.6
2.2 SOA Governance .7
3 SOA Governance .9
3.1 SOA Governance Definition.9
3.2 SOA Governance Scope .10
3.3 SOA Governance Framework.10
3.3.1 SOA Governance Reference Model (SGRM) .11
3.3.2 SOA Governance Vitality Method (SGVM).11
4 SOA Governance Reference Model (SGRM).12
4.1 SOA Governance Guiding Principles .12
4.2 SOA Governing Processes.15
4.2.1 Compliance.15
4.2.2 Dispensation .16
4.2.3 Communication .16
4.3 Governed SOA Processes .18
4.3.1 Service Portfolio Management .19
4.3.2 Service Lifecycle Management .20
4.3.3 Solution Portfolio Management .21
4.3.4 SOA Solution Lifecycle .22
4.4 SOA Governance Roles and Responsibilities.24
4.5 SOA Governance Process Artifacts.27
4.6 SOA Governance Technology .29
5 SOA Governance Vitality Method (SGVM).30
5.1 Plan Phase.31
5.1.1 Understand Current Governance Structures.31
5.1.2 Assess SOA Maturity .32
5.1.3 Develop SOA Governance Vision and Strategy.33
5.1.4 Develop SOA Governance Scope .33
5.1.5 Develop SOA Governance Principles .33
5.1.6 Develop SOA Governance Roadmap.34
SOA Governance Framework iii
© ISO/IEC 2012 – All rights reserved
5.2 Define Phase .34
5.2.1 Define Governed SOA Processes.35
5.2.2 Define Governing SOA Processes.36
5.2.3 Collect SOA Guidelines and Standards.36
5.2.4 Define SOA Governance Organization, Roles, and
Responsibilities .36
5.2.5 Define SOA Governance Information Artifacts.36
5.2.6 Define SOA Governance Environment .37
5.2.7 Create Transition Plans .37
5.3 Implement Phase.38
5.3.1 SOA Governance Organization Transition Plan
Implementation.39
5.3.2 SOA Governance Process Transition Plan
Implementation.40
5.3.3 SOA Governance Technology Transition Plan
Implementation.40
5.4 Monitor Phase.41
5.4.1 Monitor and Evaluate SOA Governed Processes.42
5.4.2 Monitor and Evaluate SOA Governing Processes.42
5.4.3 Monitor External Changes.42
5.4.4 Monitor and Evaluate SOA Guidelines Development .43
5.5 SGVM Use of SOA Governance Artifacts .43
A SOA Governance Process Activities.45
A.1 SOA Governing Processes.45
A.2 SOA Governed Processes .48
B SOA Governance Process Information Entities.72
B.1 SOA Governing Process Artifacts .73
B.2 SOA Governed Process Artifacts.73
B.3 SGVM Artifacts.79
C SOA Governance Metrics Example .81
D Relationships with Other SOA Standards .83
iv Technical Standard (2009)
© ISO/IEC 2012 – All rights reserved
Preface
The Open Group
The Open Group is a vendor-neutral and technology-neutral consortium, whose vision of
Boundaryless Information Flow™ will enable access to integrated information within and
between enterprises based on open standards and global interoperability. The Open Group works
with customers, suppliers, consortia, and other standards bodies. Its role is to capture,
understand, and address current and emerging requirements, establish policies, and share best
practices; to facilitate interoperability, develop consensus, and evolve and integrate
specifications and Open Source technologies; to offer a comprehensive set of services to
enhance the operational efficiency of consortia; and to operate the industry's premier ®
certification service, including UNIX certification.
Further information on The Open Group is available at www.opengroup.org.
The Open Group has over 15 years' experience in developing and operating certification
programs and has extensive experience developing and facilitating industry adoption of test
suites used to validate conformance to an open standard or specification.
More information is available at www.opengroup.org/certification.
The Open Group publishes a wide range of technical documentation, the main part of which is
focused on development of Technical and Product Standards and Guides, but which also
includes white papers, technical studies, branding and testing documentation, and business titles.
Full details and a catalog are available at www.opengroup.org/bookstore.
As with all live documents, Technical Standards and Specifications require revision to align with
new developments and associated international standards. To distinguish between revised
specifications which are fully backwards-compatible and those which are not:
• A new Version indicates there is no change to the definitive information contained in the
previous publication of that title, but additions/extensions are included. As such, it
replaces the previous publication.
• A new Issue indicates there is substantive change to the definitive information contained
in the previous publication of that title, and there may also be additions/extensions. As
such, both previous and new documents are maintained as current publications.
Readers should note that updates – in the form of Corrigenda – may apply to any publication.
This information is published at www.opengroup.org/corrigenda.
This Document
This document is the Technical Standard for the SOA Governance Framework. It has been
developed by the SOA Governance project of The Open Group SOA Working Group.
SOA Governance Framework v
© ISO/IEC 2012 – All rights reserved
Trademarks
™ ™ ®
Boundaryless Information Flow and TOGAF are trademarks and Making Standards Work ,
® ®
The Open Group , UNIX , and the “X” device are registered trademarks of The Open Group in
...
Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.