Tips to Protect your APIs
Suman Tiwari

Tips to Protect your APIs

  1. Use Strong Authentication mechanism
  2. Role Based Access Control
  3. Rate Limiting
  4. Encryption at Rest
  5. Encryption at Transit
  6. MFA
  7. Security Headers
  8. Set Token Expiry
  9. Safe API documentation (Don' Reveal sensitive information)
  10. Error Handling
  11. Use Anti CSRF/XSRF Token
  12. Cross Origin Resource sharing hardening
  13. Input Sanitization and neutralization
  14. Logging and Auditing
  15. Version Control
  16. Data Validation on receiving, processing and transmitting
  17. Session Management
  18. Regular Updates and Patches
  19. API Security Testing
  20. Refer OWASP API Security Project

Suman Tiwari

Cloud and Application Security Architect Stamp 4 CISA | ISO27001 LA | CEH | CPISI | Certified ScrumMaster(CSM)

1 个月

Nice Read on this topic: The Eight Components Of API Security: https://reprints2.forrester.com/#/assets/2/1403/RES179903/report

回复
Raja Mukherjee

Technology Security Associate Manager

7 个月

Nice one

要查看或添加评论,请登录

Suman Tiwari的更多文章

  • Cool method to Track your lost android device

    Cool method to Track your lost android device

    We are so well connected to our gadgets like cellphone that for most of us losing a phone is like losing a body part…

    3 条评论
  • Questions asked in CPISI Exam

    Questions asked in CPISI Exam

    If you are going to take CPISI (Certified Payment Card Industry Security Implementer Version 3.2) exam conducted by…

    14 条评论
  • Credit Card Validation Tool (offline)

    Credit Card Validation Tool (offline)

    This is standalone Credit card tool which can be used to verify valid credit card number (Internet is not required)…

    2 条评论
  • How to Add CAPTCHA in WordPress?

    How to Add CAPTCHA in WordPress?

    Want to stop Bots and Spammers? Well, if your site is developed using WordPress than you are at right place. This…

    6 条评论
  • Sharing some well known Secure Coding Standards and guidelines

    Sharing some well known Secure Coding Standards and guidelines

    Sharing some well known Secure Coding Standards and guidelines 1. Secure Coding Standard Microsoft: https://msdn.

社区洞察

其他会员也浏览了