The National Institute of Standards and Technology has published a new special publication, titled “Guidelines for API Protection for Cloud-Native Systems.”
SP 800-228, authored by NIST’s Ramaswamy Chandramouli and Tetrate principal engineer Zack Butcher, provides guidelines on how to safeguard application programming interfaces, or APIs, to ensure the overall security of cloud-native enterprise IT systems.
Table of Contents
Securing Enterprise IT Systems
The publication outlines a systematic approach to identifying and analyzing potential vulnerabilities during API development and deployment. It suggests using basic and advanced controls and other measures designed to protect APIs during their lifecycle. Finally, the document emphasizes the need for security practitioners to evaluate the pros and cons of different control implementation patterns so they can implement API security approaches based on a risk-based strategy.
What Are Application Programming Interfaces?
An API is a set of rules and protocols that enable communication between software applications. Modern enterprise IT infrastructures depend on APIs to integrate and streamline business operations.