OWASP API Security Top 10 - 2023
Misconfiguration and Secure Design

OWASP API Security Top 10 - 2023 OWASPAPI-6: Security Misconfiguration and Secure API Design

Address API8:2023 Security Misconfiguration + OWASP-API-PRG-01 Secure API Design and Threat Modelling per OWASP API Security Top 10 2023. Security Misconfiguration occurs when API or its supporting stack has security headers + permissions + protocols + or features improperly configured. Mitigations include (a) implement hardened baseline configurations across API stack + cloud infrastructure + (b) maintain configuration management with drift detection + remediation + (c) apply security headers (HSTS + CSP + X-Content-Type-Options + similar where applicable) + (d) disable unnecessary features + endpoints + verbose error messages + debug endpoints, (e) maintain CORS configuration + appropriate to actual use cases, (f) use up-to-date TLS + cipher suites. Secure API Design and Threat Modelling (OWASP-API-PRG-01) must (a) conduct threat modelling at design phase + (b) document threat model per API + revisit on significant change + (c) integrate with broader SDLC.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 110 controls across 83 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

MARS-E · 3 controls

  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

API 1164 · 2 controls

  • API1164-14 Physical Security
  • API1164-22 Configuration management for OT systems

FISMA · 2 controls

  • FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting
  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200

FedRAMP Rev 5 · 2 controls

  • FedRAMP-Baselines FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters
  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • GhCSA-Service-Provider-Licensing-Professional Cybersecurity Service Provider Licensing and Professional Accreditation

ISMAP (Japan) · 2 controls

ISO/IEC 27400:2022 · 2 controls

  • 27400-6.2 Device Identity and Authentication
  • 27400-6.4 Default Configuration Security

MTCS (Singapore) · 2 controls

  • MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM
  • MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS

NIST SP 800-144 · 2 controls

  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access
  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration

NIST SP 800-145 · 2 controls

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening
  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour

FDA 21 CFR Part 11 · 1 control

  • Part11.30 Controls for open systems (21 CFR §11.30)

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • GAMP5-Supplier-Operations-Change-Periodic Supplier Assessment, Operational Phase, Change Control and Periodic Review

GLBA · 1 control

  • GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines

HITECH Act · 1 control

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel

HKMA SPM · 1 control

  • HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF
  • IACS-UR-E27-Equipment-Hardening-SecureConfig-Communications IACS UR E27 - Equipment Hardening + Secure Configuration + Secure Communications + Cryptography
  • 62351-9 Cyber security key management

IEEE 1686 · 1 control

  • IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection

ISO/IEC 27011:2024 · 1 control

  • 27011-8.3 Cryptography and key management
  • 29115-7.4 Level of Assurance 4 (LoA4)

India DPDP Act · 1 control

  • INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification

Indonesia PDP Law · 1 control

LGPD · 1 control

  • LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification

Liechtenstein DPA · 1 control

  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent

Mauritius DPA · 1 control

  • MU-DPA-Sensitive-Personal-Data-Section-24-Health-Biometric-Genetic-Sexual-Section-25-Children-16 Mauritius DPA Sensitive Data + Section 24 + Health + Biometric + Genetic + Sexual + Section 25 + Children 16

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent
  • MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-Transgender Minnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender
  • MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation
  • MT-CDPA-Universal-Opt-Out-Mechanism-1-January-2025-GPC-Global-Privacy-Control-Mandatory-Recognition Montana CDPA Universal Opt-Out Mechanism + 1 January 2025 + GPC + Global Privacy Control + Mandatory Recognition
  • NAIC-2 Information Security Program (ISP) - Section 4
  • AQAP2110-4 Configuration Management and Change Control
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-122 · 1 control

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit

NIST SP 800-123 · 1 control

  • NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates

NIST SP 800-137 · 1 control

  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring
  • NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

NIST SP 800-88 · 1 control

  • NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NHPA-6 Reasonable Data Security and Breach Response
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

OpenSSF Scorecard · 1 control

  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 110 it maps to, and the evidence behind each claim, over MCP and REST.