Skip to main content
Guidance

Securing HTTP-based APIs

How to ensure that application programming interfaces are designed and built securely.

Page 2 of 8

1. Secure development practices

The impact of your API being compromised could disrupt operations, damage your organisation’s reputation and may even lead to fines from regulatory bodies. It is important to establish the context before designing a system as this will ensure that any security controls are proportionate to the threats you are facing.  For example, an API used for a public weather forecasting app and an API used to manage a manufacturing line will have a totally different threat and risk profiles, which will translate to a different set of security controls.






Published

Reviewed

Version

1.0