API Security
What is API Security?
Practices and technologies for protecting application programming interfaces from attacks, abuse, and unauthorized access while ensuring proper authentication and data protection.
Terms that appear alongside api security
Each of these is named in at least one of the same controls as api security. The number is how many controls name both.
- owasp 13 shared controls
- authentication 8 shared controls
- gateway 6 shared controls
- access control 5 shared controls
- oauth 5 shared controls
- authorisation 4 shared controls
- authorization 4 shared controls
- audit 4 shared controls
Frameworks that govern api security
What the standards actually require on api security
Requirements naming api security across 6 standards, quoted from the control text.
ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →API security and access tokens. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Identity & Access in Cloud.
NIST190-10 · API security and access tokens →Implement Open Banking API security per Common Banking Industry API Standards + OAuth 2.0 + OpenID Connect (OIDC) + FAPI 2.0 (Financial-grade API) + Mutual TLS (mTLS) client authentication. Apply encryption: TLS 1.3 in transit + AES-256 at rest.
NGOB-3 · API Security Standards, mTLS, and Encryption →Address API3:2023 Broken Object Property Level Authorization (BOPLA) per OWASP API Security Top 10 2023. BOPLA combines previous API3 Excessive Data Exposure and API6 Mass Assignment categories.
OWASPAPI-3 · Broken Object Property Level Authorization (BOPLA) →Per OWASP ASVS V13: secure APIs + web services. Requirements include (a) implement authentication + authorisation consistently across all API endpoints + (b) implement input validation + output encoding + against OWASP API Security Top 10 + (c) maintain API do...
OWASPASVS-13 · API and Web Service Security (V13) →HKMA TM-G-1 adjacent modules covered in this framework's scope. TM-G-2 BUSINESS CONTINUITY PLANNING: (a) Business Continuity Governance (TM-G-2.2.1) - Board oversight + BCP committee + crisis management + RACI + ownership;
HKMA-TMG1-Adjacent-TMG2-TME1-OR2-BCP-eBanking-Resilience · TM-G-2 BCP + TM-E-1 e-Banking + OR-2 Operational Resilience Adjacent Modules →Questions people ask about api security
What is API Security?
Why is API Security important for compliance?
Which compliance frameworks address API Security?
Where can I learn more about API Security?
See how API Security applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.