Project Initiation - API Security Testing with Cyber Security Champion

Ricardo Newman

profile

Project Initiation - API Security Testing

profile
£75
60 mins
Video Meeting

About this session

API Security Assessment

Method

Our methodology is based upon our extensive experience within security testing of API and is further supported by the OWASP framework and NIST guidelines for security testing. The methodology is specifically made for API testing and covers areas such as:

  • Information Exposure
  • Configuration and Deployment Management
  • Identity Management
  • Broken Object Level Authorization
  • Broken Function Level Authorizatio
  • API Injection
  • Improper Assets Management
  • Authentication Mechanisms
  • Authorization Mechanisms
  • Session Management
  • Input Validation
  • Error Handling
  • Cryptography
  • Business Logic
  • Client-Side Attack Vectors


The test is performed as a combination of creative manual test actions and automated scans.

Involvement:

  • The delivery requires minimal involvement of your technical staff.

Value:

  • Identify vulnerabilities in a API and its resilience to cyber attacks
  • Determine if the API is developed in accordance with best practices
  • Recommendations on how to strengthen the level of security and how hardening of the API can be applied

Product - Written Report Analysis Containing the Following:

  • A non-technical section with an Executive Summary for management and decision makers
  • A technical section including detailed observations and tangible recommendations to improve the security level and hardening of the API.