bcgov / api-guidelines

BC Government API Guidelines
https://developer.gov.bc.ca/Data-and-APIs/BC-Government-API-Guidelines
Other
31 stars 10 forks source link

From NRM Information Security #13

Open mpilchar opened 5 years ago

mpilchar commented 5 years ago

Looking through the OWASP REST security recommendations, I don’t think you missed anything

https://www.owasp.org/index.php/REST_Security_Cheat_Sheet https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/REST_Security_Cheat_Sheet.md,

Perhaps providing the above reference in the doc would be helpful though as a bit more detail and examples are available there. I realize we don’t want to overload the guidelines

jeff-card commented 5 years ago

Thank you for your comment! A peer review was held on August 9th and we have the following feedback:

Good thinking - We will add a linked reference to OWASP REST as a bullet under “Security by Design”.