Planning your program
Now that you have examined the key topics of API and API security ownership and have the foundations of a maturity model, it is time for the rubber to hit the road as you begin to plan your program.
Establishing your objectives
Simon Sinek’s seminal TED talk Start with Why inspires leaders and organizations to understand their motivation for what they do and the importance of the “why” they do what they do. The same can be said for establishing an API security program – without clear objectives or raison d’etre, your program may flounder and fail. You need to understand the compelling reason(s) for implementing a change program of scale. Perhaps you process medical records and cannot risk an API breach disclosing patient data. Or maybe you are a payment processor that is bound by strict regulatory requirements. Or perhaps you are an “API-first” company whose very business succeeds (or fails) on the strength...