Are Your APIs Secure?

Robinson+Cole Data Privacy + Security Insider
Contact

[author:

Application Programming Interfaces or APIs, provide a way for programmers and developers to allow systems to exchange data with one another. For instance, all of your company’s important employee data may be contained in Active Directory (AD), but it also needs to be contained in the firm’s CRM system. Instead of having to perform tedious manual data entry of all employee moves, adds or changes, developers could leverage the APIs in the CRM system to keep AD and the CRM system in sync.

As valuable as APIs are to customers, the business and programmers, however, they are a fairly high risk as well. All sorts of potentially sensitive information could be exposed through a vulnerable API—client data, financial data, intellectual property, etc. APIs are available in almost all enterprise software platforms and cloud-based Software As A Service (SaaS) systems. Therefore, it is extremely important that you understand how to protect those APIs so they cannot be leveraged for nefarious purposes.

In fact, author Thorsten George of SecurityWeek reports that APIs are the next big cyber-attack vector according to security experts. As an example, George points to the Panera Bread breach where the company left an unauthenticated API endpoint exposed on its website. So, what might you do to secure your APIs?

  1. Approach API security the same as you would your overall security program—base it on an industry standard framework.
  2. Begin all projects with security in mind.
  3. Monitor, log and perform vulnerability scans against your APIs.
  4. Implement technology based engineering controls like API gateways.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide