OWASP API Security Top 10 - 2023
Testing + Logging + Monitoring

OWASP API Security Top 10 - 2023 OWASPAPI-8: Automated Security Testing, Logging, and Monitoring

Operate automated security testing + logging + monitoring per OWASP-API-PRG-02 + OWASP-API-PRG-03. Automated Security Testing in CI/CD must (a) integrate API security testing (SAST + DAST + IAST + API-specific tools) into CI/CD pipeline + (b) maintain test coverage for OWASP API Top 10 + business logic + authentication + authorisation + (c) implement security gates blocking deployment for critical findings + (d) maintain regression testing for known issues. API Logging Monitoring and Detection must (a) collect comprehensive API access logs including authentication + authorisation + request/response metadata + errors + (b) integrate with SIEM for correlation + detection + (c) implement anomaly detection for unusual API access patterns + abuse + automation + (d) maintain alerting + triage + investigation capability + (e) align retention with regulatory + investigative + governance requirements.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.