Explore the critical aspects of API security beyond the OWASP Top 10 in this engaging 22-minute conference talk. Delve into the essentials of creating a robust API security program at scale, covering topics such as API inventory, data protection, detection and response strategies, active testing, and the overall security journey. Learn why focusing solely on Top 10 lists is insufficient and discover practical approaches to building a comprehensive API security posture. Gain insights into pen testing, ASVS, OAuth, and various API security risks while understanding the importance of a holistic approach to API protection.
Are You Safe from OWASP #11? - Creating a Successful API Security Program