OWASP API Security Top 10 - 2023
Misconfiguration and Secure Design

OWASP API Security Top 10 - 2023 OWASPAPI-6: Security Misconfiguration and Secure API Design

Address API8:2023 Security Misconfiguration + OWASP-API-PRG-01 Secure API Design and Threat Modelling per OWASP API Security Top 10 2023. Security Misconfiguration occurs when API or its supporting stack has security headers + permissions + protocols + or features improperly configured. Mitigations include (a) implement hardened baseline configurations across API stack + cloud infrastructure + (b) maintain configuration management with drift detection + remediation + (c) apply security headers (HSTS + CSP + X-Content-Type-Options + similar where applicable) + (d) disable unnecessary features + endpoints + verbose error messages + debug endpoints, (e) maintain CORS configuration + appropriate to actual use cases, (f) use up-to-date TLS + cipher suites. Secure API Design and Threat Modelling (OWASP-API-PRG-01) must (a) conduct threat modelling at design phase + (b) document threat model per API + revisit on significant change + (c) integrate with broader SDLC.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.