API Security Policy | DefectDojo Trust Center

API Security Policy

1. Purpose

The purpose of this policy is to inform all DefectDojo employees and external parties with access to DefectDojo equipment, systems, or networks (DefectDojo Staff) of their obligations with regards to the security of Application Programming Interfaces (APIs) of all systems, networks, IT assets, and licensed software owned, operated, or used by DefectDojo.

2. Scope

API security as applied to information security and the confidentiality, integrity, and availability of company-owned, processed, stored, and transmitted information via APIs.

3. Compliance

3.1 Compliance Measurement

The Information Security Management team will verify compliance to this document through various methods, including but not limited to business tool reports, internal and external audits, and feedback to the document owner.

3.2 Exceptions

Any exception to this document must be reviewed and approved in advance by the Management Review Team.

3.3 Non-Compliance

Any DefectDojo Staff found to have violated this document may be subject to disciplinary action, up to and including termination of employment.

3.4 Continual Improvement

This document is updated and reviewed as part of the continual improvement and process.

4. Requirements

4.1 Authentication

4.2 Authorization

4.2.1 Function Level Authorization

4.3 Create and Update an API Inventory

4.4 Implement Strong Encryption Mechanisms

4.5 Use Quotas and Throttling to Limit Requests

4.6 API Scanner for Vulnerabilities

4.7 Data Protection

4.7.1 Binding client-provided data

4.8 Resources and Rate-Limiting

4.9 Security Configuration

4.10 Logging and Monitoring

5. Relevant Documents