Microservices Architecture All MIS603
6/3/2020 Laureate International Universities
https://laureate-au.blackboard.com/webapps/blackboard/content/listContent.jsp?course_id=_89956_1&content_id=_8971658_1&mode=reset 1/6
MODULE 5 TOPIC 2 RESOURCES AND ACTIVITIESMODULE 5 TOPIC 2 RESOURCES AND ACTIVITIES
Risk and Governance
Introduction:
ISACA is a global professional association focused on aiding IT governance, assurance,
control, risk, and information security. They are not the only professional body to
concern themselves with governance and there are several extant frameworks,
models and standards concerned with helping organisations to achieve better
governance. These would include, but not be limited to: ITIL for IT Service
Management, and ISO 38500. However, ISACA’s COBIT is a well-recognised and
adopted IT governance control framework. Governance is concerned with �ve
domains: Value delivery, strategic alignment, performance management, resource
management, and the area topical to this module – risk management. Thus, to better
manage risk and data security we need to look to governance as a means to help the
organisation to meet their legal and regulatory obligations.
Lester’s video’s (2019) explain about the broad IT governance and risk management
process. Please note how areas directly associated with microservices architecture fall
into the various areas of security governance: communications and network security,
identity and access management, and software development security. It is important
6/3/2020 Laureate International Universities
https://laureate-au.blackboard.com/webapps/blackboard/content/listContent.jsp?course_id=_89956_1&content_id=_8971658_1&mode=reset 2/6
to note that the spirit of governance is about creating processes and policies that
create value and prevent loss – they are about identifying vulnerabilities and threats
and formulating countermeasures to make deliberate decisions about how risks will
be managed: will the risk be mitigated, transferred, avoided or accepted?
References
ISACA, (n.d). About us. Retrieved from https://www.isaca.org/why-isaca/about-us
Resources and Activities:
IT Governance
Please watch the following video from the CISA Cert Prep: Information
technology governance and management for IS auditors series:
1.Governance: IT Governance (8m 16 s)
This video will give you a broad understanding of IT governance. We are
concerned with a better understanding of security governance and the
governance of risk. While it is recommended that you watch the whole
video to orient yourself in the concept of IT governance, the area to watch
with particular interest is at the 6m30s mark where Lester discussed the
security governance sub-element of IT governance and how security and
risk are managed. As you can see, the areas of concern within security
governance are applicable to microservices architecture: asset security,
communications, and network security, identify and access management,
security assessment and testing, and �nally software development security.
Microservices architecture is as with any software development is subject to
the requirements of IT and security governance.
Reference:
Lester, M. (2018, January, 30). Governance: IT governance [Video �le].
Retrieved from https://www.linkedin.com/learning-login/share?
forceAccount=false&redirect=https%3A%2F%2Fwww.linkedin.com%2Flearning%
cert-prep-2-information-technology-governance-and-management-for-is-
auditors%3Ftrk%3Dshare_ent_url&account=56744473
(https://www.linkedin.com/learning-login/share?
forceAccount=false&redirect=https%3A%2F%2Fwww.linkedin.com%2Flearning%
cert-prep-2-information-technology-governance-and-management-for-is-
auditors%3Ftrk%3Dshare_ent_url&account=56744473)
6/3/2020 Laureate International Universities
https://laureate-au.blackboard.com/webapps/blackboard/content/listContent.jsp?course_id=_89956_1&content_id=_8971658_1&mode=reset 3/6
The risk management process
Please watch the following video from the CISA Cert Prep: Information
technology governance and management for IS auditors series:
3.Risk management: Risk management process (3m 19 s)
In this video Lester outlines the risk management process in organisations.
You will �nd valuable information in this video about the risk analysis
process and key de�nitions of elements of risk: vulnerability, threat, and
countermeasures. Note the risk management matrix and quadrants at
1m42s in the video as this is a useful tool for analysing, evaluating, and
quantifying di�erent risks.
Reference:
Lester, M. (2018, January, 30). Risk management: Risk management process
[Video �le]. Retrieved from https://www.linkedin.com/learning-login/share?
forceAccount=false&redirect=https%3A%2F%2Fwww.linkedin.com%2Flearning%
cert-prep-2-information-technology-governance-and-management-for-is-
auditors%3Ftrk%3Dshare_ent_url&account=56744473
(https://www.linkedin.com/learning-login/share?
forceAccount=false&redirect=https%3A%2F%2Fwww.linkedin.com%2Flearning%
cert-prep-2-information-technology-governance-and-management-for-is-
auditors%3Ftrk%3Dshare_ent_url&account=56744473)
How do I govern a microservice system?
Please read pp. 111 - 112. This reading o�ers three distinct options for
addressing security and governance requirements in microservices
architecture: Centralized, decentralized and contextual controls. Di�erent
controls methods o�er bene�ts and drawbacks that may make them more
or less aligned to achieving the goals of rapid deployment of working code.
Please read through each section and identify where the approach is more
or less aligned to the goals and objectives of microservices architecture.
Reference:
Nadareishvili, I., Mitra, R., McLarty, M., & Amundsen, M. (2016). Microservice
architecture: Aligning principles, practices, and culture. California, USA:
O’Reilly. Retrieved from https://ebookcentral-proquest-
com.ezproxy.laureate.net.au/lib/think/reader.action?
6/3/2020 Laureate International Universities
https://laureate-au.blackboard.com/webapps/blackboard/content/listContent.jsp?course_id=_89956_1&content_id=_8971658_1&mode=reset 4/6
docID=4602504&ppg11=127 (https://ebookcentral-proquest-
com.ezproxy.laureate.net.au/lib/think/reader.action?
docID=4602504&ppg11=127)
Governance through code
Please read pp. 22 – 24. As we have progressed through this module, we
have stated that security is everybody’s concern – and so it is with
governance – everybody contributes to the success of governance activities.
Newman identi�es that following guidelines may be considered onerous on
developers and recommends a number of strategies to help improve
compliance with governance requirement: exemplars, tailored service
templates, understanding technical debt which needs to be avoided or ‘paid
down’ and exception handling. Newman sees it to be the architect’s role to
assist developers by guiding them through governance thinking and
decisions.
Reference:
Newman, S. (2015). Building microservices: Designing �ne-grained systems.
California, USA: O’Reilly Media. Retrieved from https://ebookcentral-
proquest-com.ezproxy.laureate.net.au/lib/think/reader.action?
docID=1938300&ppg=42 (https://ebookcentral-proquest-
com.ezproxy.laureate.net.au/lib/think/reader.action?
docID=1938300&ppg=42)
Governance and Leading from the Center
Please read pp. 25 – 26. Newman outlines the responsibility of architects to
ensure that good governance is supported in alignment with the COBIT
framework. He indicates that a group or committee can be an e�ective
governance instrument to discuss and formulate ways of addressing
microservices architecture security and risk management requirements.
Note that it is Newman’s opinion that governance should be in�uenced by
those working on microservices and that this group should be responsible
for managing technical risk.
Reference:
6/3/2020 Laureate International Universities
https://laureate-au.blackboard.com/webapps/blackboard/content/listContent.jsp?course_id=_89956_1&content_id=_8971658_1&mode=reset 5/6
Newman, S. (2015). Building microservices: Designing �ne-grained systems.
California, USA: O’Reilly Media. Retrieved from https://ebookcentral-
proquest-com.ezproxy.laureate.net.au/lib/think/reader.action?
docID=1938300&ppg=45 (https://ebookcentral-proquest-
com.ezproxy.laureate.net.au/lib/think/reader.action?
docID=1938300&ppg=45)
Additional Learning Resources
If you would like to learn more about the topics covered in this module, here are
some additional resources. These resources will contribute to further develop
understanding of the topics covered. However, these resources are not essential
to complete this module or the assessments associated with this subject.
This brief article explains what the COBIT framework is and how it
supports businesses to create strategies around information
management and governance with a view to - amongst other
goals - managing and mitigating risk.
Reference:
White, S. (2019, January). What is COBIT? A framework for alignment and
governance. CIO. Retrieved from
https://www.cio.com/article/3243684/what-is-cobit-a-framework-for-
alignment-and-governance.html
(https://www.cio.com/article/3243684/what-is-cobit-a-framework-for-
alignment-and-governance.html)
Learning Activity 1: Interactive Knowledge check
Learning Activity 2: Technical debt Discussion forum post
Collaborative learning activity: Governance in Microservices
Architecture
6/3/2020 Laureate International Universities
https://laureate-au.blackboard.com/webapps/blackboard/content/listContent.jsp?course_id=_89956_1&content_id=_8971658_1&mode=reset 6/6
Note: The Learning activities above are not part of summative/graded assessment;
however they are designed to prepare you for incremental graded assessment and
expand your learning.
These activities encourage a community learning experience between peers, and
provide opportunities for facilitators to o�er formative feedback, throughout a
module, to the student cohort.