# SP-030 API Security

Status: active. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Comprehensive security pattern for protecting application programming interfaces across their full lifecycle. Maps 45 NIST 800-53 controls to the critical security functions required to defend APIs against the OWASP API Security Top 10: authentication, authorization, input validation, rate limiting, transport security, inventory management, and continuous monitoring.
Use when: This pattern applies to any organisation that exposes or consumes APIs. It is essential for organisations with public-facing APIs accessed by third-party developers, mobile applications that communicate via REST or GraphQL APIs, microservice architectures with significant service-to-service API traffic, open banking or PSD2 compliance requirements, partner integration programmes with API-based data exchange, IoT...
Not when: This pattern adds unnecessary overhead for purely internal monolithic applications that do not expose APIs.

## Controls (45, NIST SP 800-53 ids)
- Critical (14): AC-03, AC-04, AC-06, AC-07, AU-02, CA-07, CM-08, IA-02, IA-05, IA-09, SC-07, SC-08, SI-04, SI-10
- Important (24): AC-12, AC-17, AC-20, AC-21, AU-03, AU-06, AU-12, CA-02, CM-02, CM-03, CM-07, IA-04, IA-08, IR-04, IR-05, PL-08, RA-03, RA-05, SA-08, SA-11, SC-13, SC-23, SI-11, SI-15
- Standard (7): AC-10, AT-02, AT-03, SC-28, SI-03, SR-02, SR-03

## What each critical control mitigates (14)
- AC-03 Access Enforcement: T-API-002, T-API-006
- AC-04 Information Flow Enforcement: T-API-003, T-API-004, T-API-007
- AC-06 Least Privilege: T-API-002, T-API-004
- AC-07 Unsuccessful Logon Attempts: T-API-001, T-API-005, T-API-012
- AU-02 Event Logging: none of the threats below
- CA-07 Continuous Monitoring: T-API-010, T-API-012
- CM-08 System Component Inventory: T-API-010
- IA-02 Identification and Authentication (Organizational Users): T-API-001
- IA-05 Authenticator Management: T-API-001, T-API-011
- IA-09 Service Identification and Authentication: T-API-009
- SC-07 Boundary Protection: T-API-005, T-API-007, T-API-012
- SC-08 Transmission Confidentiality and Integrity: T-API-009
- SI-04 System Monitoring: T-API-001, T-API-002, T-API-005, T-API-008, T-API-011
- SI-10 Information Input Validation: T-API-003, T-API-006, T-API-007, T-API-012

## Threats and the controls that mitigate them (12)
- T-API-001 Broken authentication and credential stuffing: IA-02, IA-05, AC-07, SI-04
- T-API-002 Broken object level authorization (BOLA/IDOR): AC-03, AC-06, AU-06, SI-04
- T-API-003 Injection attacks via API parameters: SI-10, SI-03, SI-11, AC-04
- T-API-004 Excessive data exposure in API responses: SI-15, AC-04, AC-06, AU-06
- T-API-005 Rate limiting bypass and API abuse: AC-07, AC-10, SC-07, SI-04
- T-API-006 Mass assignment and parameter tampering: SI-10, AC-03, CM-02, SA-08
- T-API-007 Server-side request forgery via API input: SI-10, SC-07, AC-04, SI-03
- T-API-008 Third-party API supply chain compromise: AC-20, SR-02, SR-03, SI-04
- T-API-009 Man-in-the-middle on API traffic: SC-08, SC-13, SC-23, IA-09
- T-API-010 Shadow API and zombie API exposure: CM-08, CM-07, RA-05, CA-07
- T-API-011 Token theft and replay attacks: SC-23, AC-12, IA-05, SI-04
- T-API-012 API denial of service via resource exhaustion: AC-07, SC-07, SI-10, CA-07

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-030/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-030/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 31 KB: /api/v1/patterns/SP-030
- Page for people: /patterns/sp-030/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-002 Server Module; SP-004 SOA Publication and Location Pattern; SP-005 SOA Internal Service Usage Pattern; SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-016 DMZ Module; SP-028 Secure DevOps Pipeline; SP-029 Zero Trust Architecture

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
