- Use Strong Authentication mechanism
- Role Based Access Control
- Rate Limiting
- Encryption at Rest
- Encryption at Transit
- MFA
- Security Headers
- Set Token Expiry
- Safe API documentation (Don' Reveal sensitive information)
- Error Handling
- Use Anti CSRF/XSRF Token
- Cross Origin Resource sharing hardening
- Input Sanitization and neutralization
- Logging and Auditing
- Version Control
- Data Validation on receiving, processing and transmitting
- Session Management
- Regular Updates and Patches
- API Security Testing
- Refer OWASP API Security Project
Cloud and Application Security Architect Stamp 4 CISA | ISO27001 LA | CEH | CPISI | Certified ScrumMaster(CSM)
1 个月Nice Read on this topic: The Eight Components Of API Security: https://reprints2.forrester.com/#/assets/2/1403/RES179903/report
Technology Security Associate Manager
7 个月Nice one