So i took the ASVS, got it down to under 50 controls. Decided whether the controls could be tested thru automation or manually. This will be the start of my api security standard.

Comments