Cyver core supports the OWASP API Security TOP 10 Checklist, providing full coverage for both the 2019 and the most current 2023 versions. This standard is designed to help organizations understand and mitigate the unique security risks of modern Application Programming Interfaces (APIs).
In today's application-driven world, APIs are fundamental to everything from mobile and SaaS applications to IoT and internal systems. Because they expose application logic and sensitive data like PII, APIs have become a critical and growing target for attackers.
What is API Security?
API Security encompasses the strategies and solutions used to understand and mitigate the unique vulnerabilities and security risks of APIs. Ensuring API security is non-negotiable for rapid and trustworthy innovation across any modern digital infrastructure.
The Most Critical API Security Risks (2023 Edition)
- API1:2023 - Broken Object Level Authorization
- API2:2023 - Broken Authentication
- API3:2023 - Broken Object Property Level Authorization
- API4:2023 - Unrestricted Resource Consumption
- API5:2023 - Broken Function Level Authorization
- API6:2023 - Unrestricted Access to Sensitive Business Flows
- API7:2023 - Server Side Request Forgery
- API8:2023 - Security Misconfiguration
- API9:2023 - Improper Inventory Management
- API10:2023 - Unsafe Consumption of APIs
Download
You can directly download the latest OWASP API Security TOP 10 Checklist from our GitHub repository:
OWASP API Security Top 10 - 2023