• Hi @JSwindle018785 (Community Member)​ , this is not something we currently have policy standard support for and is not on the near term roadmap. We are watching the project to see which direction it takes; right now the API Security Top 10 is very closely related to the regular OWASP Top 10, and some of the places it diverges (authorization issues, data classification) are not easily tested for via automation and better suited for manual testing.

     

    We'd love to hear more about how you'd like to use this standard; are there additional types of risk you think we should be testing for via automation? Is it valuable to be able to show a clean test against the OWASP API Security Top 10 standard to an external stakeholder?

    Expand Post
  • JSwindle018785 (Community Member)

    Thanks. I believe it is valuable to have documentation for the overlap between API Security Top 10 and OWASP Top 10. That would allow us to produce documentation of what from API Security Top 10 is covered by Veracode scans. We'd then produce internal documentation of coverage for what's not covered.

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.