Skip to content
arrow_back
search
ISM-1851 policy ASD Information Security Manual (ISM)

Secure Development Using OWASP API Security Top 10

Web API developers must address the top 10 security risks identified by OWASP to ensure safety.

record_voice_over

Plain language

When developing web applications, it's crucial to focus on the top security risks identified by the OWASP (Open Web Application Security Project) for APIs. If not addressed, these risks can make your application vulnerable to attacks, which might lead to data theft or disruption of services, potentially damaging your reputation and trust with customers.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The OWASP API Security Top 10 are mitigated in the development of web APIs.
policy ASD Information Security Manual (ISM) ISM-1851
priority_high

Why it matters

Without addressing the OWASP API Security Top 10, web APIs may allow unauthorised access, data exposure, and business disruption, harming trust and finances.

settings

Operational notes

Map API threats to the OWASP API Security Top 10; test authn/authz, validate inputs, and harden endpoints to prevent common API exploits.

Mapping detail

Mapping

Direction

Controls