<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=David+Shaw</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=David+Shaw"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/David_Shaw"/>
		<updated>2026-05-31T13:25:03Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=205638</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=205638"/>
				<updated>2015-12-29T17:43:14Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* November 19th, 2015 Meeting */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:140px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Owasp_santa_barbara.png|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;!--{{Chapter Template|chaptername=Santa_Barbara|extra=The current Chapter Leaders are: [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=OWASP Santa Barbara=&lt;br /&gt;
Welcome to the wiki page of the OWASP Chapter in beautiful '''Santa Barbara, California!''' We're excited to have a dedicated core group of application security professionals and enthusiasts, and we'd love to have you attend a meeting -- they're all free, and there's (almost) always pizza!&lt;br /&gt;
&lt;br /&gt;
The first step to becoming involved is to '''join our [http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara mailing list].''' This is a very low-volume list, so you don't need to worry about your inbox getting overloaded. It's important to join because meetings are planned and discussed on the list, and it's an easy way to stay informed. In addition to the mailing list, we're posting each of our meetings on our '''[http://www.meetup.com/Santa-Barbara-OWASP-Chapter/ MeetUp group]'''.&lt;br /&gt;
&lt;br /&gt;
OWASP Santa Barbara meetings will also be listed on this wiki page. Whenever talks are recorded, they'll be posted here; upcoming meetings will always be listed on this page, as well as summaries of previous meetings.&lt;br /&gt;
&lt;br /&gt;
We hope to see you soon!&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== January, 2016 Meeting ==&lt;br /&gt;
&lt;br /&gt;
Details TBD&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
'''November 19th, 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' 6pm on Thursday, November 19th, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker/Discussion:''' Jason Haddix, followed by open discussion&lt;br /&gt;
&lt;br /&gt;
'''Notes:''' Parking is available in the (large) AppFolio parking lot, so no need to worry about that. Meeting is inside the building, upstairs.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=205636</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=205636"/>
				<updated>2015-12-29T17:42:59Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Previous Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:140px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Owasp_santa_barbara.png|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;!--{{Chapter Template|chaptername=Santa_Barbara|extra=The current Chapter Leaders are: [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=OWASP Santa Barbara=&lt;br /&gt;
Welcome to the wiki page of the OWASP Chapter in beautiful '''Santa Barbara, California!''' We're excited to have a dedicated core group of application security professionals and enthusiasts, and we'd love to have you attend a meeting -- they're all free, and there's (almost) always pizza!&lt;br /&gt;
&lt;br /&gt;
The first step to becoming involved is to '''join our [http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara mailing list].''' This is a very low-volume list, so you don't need to worry about your inbox getting overloaded. It's important to join because meetings are planned and discussed on the list, and it's an easy way to stay informed. In addition to the mailing list, we're posting each of our meetings on our '''[http://www.meetup.com/Santa-Barbara-OWASP-Chapter/ MeetUp group]'''.&lt;br /&gt;
&lt;br /&gt;
OWASP Santa Barbara meetings will also be listed on this wiki page. Whenever talks are recorded, they'll be posted here; upcoming meetings will always be listed on this page, as well as summaries of previous meetings.&lt;br /&gt;
&lt;br /&gt;
We hope to see you soon!&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== January, 2016 Meeting ==&lt;br /&gt;
&lt;br /&gt;
Details TBD&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
== November 19th, 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' 6pm on Thursday, November 19th, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker/Discussion:''' Jason Haddix, followed by open discussion&lt;br /&gt;
&lt;br /&gt;
'''Notes:''' Parking is available in the (large) AppFolio parking lot, so no need to worry about that. Meeting is inside the building, upstairs.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=205635</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=205635"/>
				<updated>2015-12-29T17:42:42Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Upcoming Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:140px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Owasp_santa_barbara.png|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;!--{{Chapter Template|chaptername=Santa_Barbara|extra=The current Chapter Leaders are: [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=OWASP Santa Barbara=&lt;br /&gt;
Welcome to the wiki page of the OWASP Chapter in beautiful '''Santa Barbara, California!''' We're excited to have a dedicated core group of application security professionals and enthusiasts, and we'd love to have you attend a meeting -- they're all free, and there's (almost) always pizza!&lt;br /&gt;
&lt;br /&gt;
The first step to becoming involved is to '''join our [http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara mailing list].''' This is a very low-volume list, so you don't need to worry about your inbox getting overloaded. It's important to join because meetings are planned and discussed on the list, and it's an easy way to stay informed. In addition to the mailing list, we're posting each of our meetings on our '''[http://www.meetup.com/Santa-Barbara-OWASP-Chapter/ MeetUp group]'''.&lt;br /&gt;
&lt;br /&gt;
OWASP Santa Barbara meetings will also be listed on this wiki page. Whenever talks are recorded, they'll be posted here; upcoming meetings will always be listed on this page, as well as summaries of previous meetings.&lt;br /&gt;
&lt;br /&gt;
We hope to see you soon!&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== January, 2016 Meeting ==&lt;br /&gt;
&lt;br /&gt;
Details TBD&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=204477</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=204477"/>
				<updated>2015-12-03T17:58:23Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Road Map and Getting Involved */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project is designed to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
The primary deliverables of this project are the '''OWASP Top Ten API Security Risks''' and a secure API development '''documentation portal.'''&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
The initial version of this document, including an up-to-date table of contents, is available [https://www.owasp.org/images/f/f6/Owasp_api_security_toc.pdf here].&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQ=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
* Publish and Publicize Top Ten API Security Risks&lt;br /&gt;
* Use data gathered in process to &amp;quot;reverse&amp;quot; the Top Ten, in order to create a Secure Development deliverable for APIs&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the [https://www.owasp.org/index.php/OWASP_API_Security_Project primary wiki page] to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=203559</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=203559"/>
				<updated>2015-11-18T22:05:17Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Project About */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project is designed to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
The primary deliverables of this project are the '''OWASP Top Ten API Security Risks''' and a secure API development '''documentation portal.'''&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
The initial version of this document, including an up-to-date table of contents, is available [https://www.owasp.org/images/f/f6/Owasp_api_security_toc.pdf here].&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQ=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the [https://www.owasp.org/index.php/OWASP_API_Security_Project primary wiki page] to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=203449</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=203449"/>
				<updated>2015-11-17T00:19:34Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:140px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Owasp_santa_barbara.png|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;!--{{Chapter Template|chaptername=Santa_Barbara|extra=The current Chapter Leaders are: [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=OWASP Santa Barbara=&lt;br /&gt;
Welcome to the wiki page of the OWASP Chapter in beautiful '''Santa Barbara, California!''' We're excited to have a dedicated core group of application security professionals and enthusiasts, and we'd love to have you attend a meeting -- they're all free, and there's (almost) always pizza!&lt;br /&gt;
&lt;br /&gt;
The first step to becoming involved is to '''join our [http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara mailing list].''' This is a very low-volume list, so you don't need to worry about your inbox getting overloaded. It's important to join because meetings are planned and discussed on the list, and it's an easy way to stay informed. In addition to the mailing list, we're posting each of our meetings on our '''[http://www.meetup.com/Santa-Barbara-OWASP-Chapter/ MeetUp group]'''.&lt;br /&gt;
&lt;br /&gt;
OWASP Santa Barbara meetings will also be listed on this wiki page. Whenever talks are recorded, they'll be posted here; upcoming meetings will always be listed on this page, as well as summaries of previous meetings.&lt;br /&gt;
&lt;br /&gt;
We hope to see you soon!&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== November 19th, 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' 6pm on Thursday, November 19th, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker/Discussion:''' Jason Haddix, followed by open discussion&lt;br /&gt;
&lt;br /&gt;
'''Notes:''' Parking is available in the (large) AppFolio parking lot, so no need to worry about that. Meeting is inside the building, upstairs.&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=203248</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=203248"/>
				<updated>2015-11-09T23:30:28Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Quick Download */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project is designed to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
The primary deliverables of this project are the '''OWASP Top Ten API Security Risks''' and a secure API development '''documentation portal.'''&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
The initial version of this document, including an up-to-date table of contents, is available [https://www.owasp.org/images/f/f6/Owasp_api_security_toc.pdf here].&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQ=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=203247</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=203247"/>
				<updated>2015-11-09T23:30:04Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Quick Download */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project is designed to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
The primary deliverables of this project are the '''OWASP Top Ten API Security Risks''' and a secure API development '''documentation portal.'''&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
The initial version of this document, including an up-to-date table of contents, is available [here https://www.owasp.org/images/f/f6/Owasp_api_security_toc.pdf].&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQ=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Owasp_api_security_toc.pdf&amp;diff=203246</id>
		<title>File:Owasp api security toc.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Owasp_api_security_toc.pdf&amp;diff=203246"/>
				<updated>2015-11-09T23:29:05Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: API Security Project Table of Contents&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;API Security Project Table of Contents&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202515</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202515"/>
				<updated>2015-10-22T18:54:13Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* What is this project? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project is designed to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
The primary deliverables of this project are the '''OWASP Top Ten API Security Risks''' and a secure API development '''documentation portal.'''&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download '''here'''.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQ=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202394</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202394"/>
				<updated>2015-10-20T23:49:40Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* November 2015 Meeting */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:140px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Owasp_santa_barbara.png|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;!--{{Chapter Template|chaptername=Santa_Barbara|extra=The current Chapter Leaders are: [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=OWASP Santa Barbara=&lt;br /&gt;
Welcome to the wiki page of the OWASP Chapter in beautiful '''Santa Barbara, California!''' We're excited to have a dedicated core group of application security professionals and enthusiasts, and we'd love to have you attend a meeting -- they're all free, and there's (almost) always pizza!&lt;br /&gt;
&lt;br /&gt;
The first step to becoming involved is to '''join our [http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara mailing list].''' This is a very low-volume list, so you don't need to worry about your inbox getting overloaded. It's important to join because meetings are planned and discussed on the list, and it's an easy way to stay informed.&lt;br /&gt;
&lt;br /&gt;
OWASP Santa Barbara meetings will also be listed on this wiki page. Whenever talks are recorded, they'll be posted here; upcoming meetings will always be listed on this page, as well as summaries of previous meetings.&lt;br /&gt;
&lt;br /&gt;
We hope to see you soon!&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== November 19th, 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' 6pm on Thursday, November 19th, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker/Discussion:''' Jason Haddix, followed by open discussion&lt;br /&gt;
&lt;br /&gt;
'''Notes:''' Parking is available in the (large) AppFolio parking lot, so no need to worry about that. Meeting is inside the building, upstairs.&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202393</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202393"/>
				<updated>2015-10-20T23:49:10Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* November 2015 Meeting */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:140px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Owasp_santa_barbara.png|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;!--{{Chapter Template|chaptername=Santa_Barbara|extra=The current Chapter Leaders are: [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=OWASP Santa Barbara=&lt;br /&gt;
Welcome to the wiki page of the OWASP Chapter in beautiful '''Santa Barbara, California!''' We're excited to have a dedicated core group of application security professionals and enthusiasts, and we'd love to have you attend a meeting -- they're all free, and there's (almost) always pizza!&lt;br /&gt;
&lt;br /&gt;
The first step to becoming involved is to '''join our [http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara mailing list].''' This is a very low-volume list, so you don't need to worry about your inbox getting overloaded. It's important to join because meetings are planned and discussed on the list, and it's an easy way to stay informed.&lt;br /&gt;
&lt;br /&gt;
OWASP Santa Barbara meetings will also be listed on this wiki page. Whenever talks are recorded, they'll be posted here; upcoming meetings will always be listed on this page, as well as summaries of previous meetings.&lt;br /&gt;
&lt;br /&gt;
We hope to see you soon!&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== November 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' 6pm on Thursday, November 19th, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker/Discussion:''' Jason Haddix, followed by open discussion&lt;br /&gt;
&lt;br /&gt;
'''Cost:''' Always free! Parking is available in the (large) AppFolio parking lot, so no need to worry about that.&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202392</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202392"/>
				<updated>2015-10-20T22:59:56Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:140px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Owasp_santa_barbara.png|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;!--{{Chapter Template|chaptername=Santa_Barbara|extra=The current Chapter Leaders are: [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=OWASP Santa Barbara=&lt;br /&gt;
Welcome to the wiki page of the OWASP Chapter in beautiful '''Santa Barbara, California!''' We're excited to have a dedicated core group of application security professionals and enthusiasts, and we'd love to have you attend a meeting -- they're all free, and there's (almost) always pizza!&lt;br /&gt;
&lt;br /&gt;
The first step to becoming involved is to '''join our [http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara mailing list].''' This is a very low-volume list, so you don't need to worry about your inbox getting overloaded. It's important to join because meetings are planned and discussed on the list, and it's an easy way to stay informed.&lt;br /&gt;
&lt;br /&gt;
OWASP Santa Barbara meetings will also be listed on this wiki page. Whenever talks are recorded, they'll be posted here; upcoming meetings will always be listed on this page, as well as summaries of previous meetings.&lt;br /&gt;
&lt;br /&gt;
We hope to see you soon!&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== November 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' '''6pm''' on Thursday, '''November 19th''', 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker/Discussion:''' TBA&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Cost:''' Free!&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202391</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202391"/>
				<updated>2015-10-20T22:54:36Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:140px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Owasp_santa_barbara.png|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{{Chapter Template|chaptername=Santa_Barbara|extra=The current Chapter Leaders are: [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== November 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' '''6pm''' on Thursday, '''November 19th''', 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker/Discussion:''' TBA&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Cost:''' Free!&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202390</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202390"/>
				<updated>2015-10-20T22:53:29Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:140px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Owasp_santa_barbara.png|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{{Chapter Template|chaptername=Santa_Barbara|extra=The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== November 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' '''6pm''' on Thursday, '''November 19th''', 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker/Discussion:''' TBA&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Cost:''' Free!&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202389</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202389"/>
				<updated>2015-10-20T22:51:51Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Owasp_santa_barbara.png|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Santa_Barbara|extra=The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== November 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' '''6pm''' on Thursday, '''November 19th''', 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker/Discussion:''' TBA&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Cost:''' Free!&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Owasp_santa_barbara.png&amp;diff=202388</id>
		<title>File:Owasp santa barbara.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Owasp_santa_barbara.png&amp;diff=202388"/>
				<updated>2015-10-20T22:50:38Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: OWASP Santa Barbara header image&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP Santa Barbara header image&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202384</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202384"/>
				<updated>2015-10-20T19:00:25Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* FAQs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project is designed to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download '''here'''.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQ=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202383</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202383"/>
				<updated>2015-10-20T18:59:45Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* November 2015 Meeting */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Santa_Barbara|extra=The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== November 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' '''6pm''' on Thursday, '''November 19th''', 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker/Discussion:''' TBA&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Cost:''' Free!&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202382</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202382"/>
				<updated>2015-10-20T18:58:30Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* OWASP API Security Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project is designed to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download '''here'''.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202381</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202381"/>
				<updated>2015-10-20T18:57:51Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: Undo revision 202380 by David Shaw (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download '''here'''.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202380</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202380"/>
				<updated>2015-10-20T18:57:29Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Related Projects */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [ESAPI Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download '''here'''.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202377</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202377"/>
				<updated>2015-10-20T18:31:31Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Quick Download */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download '''here'''.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202376</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202376"/>
				<updated>2015-10-20T18:31:07Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* What is the this project? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202375</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202375"/>
				<updated>2015-10-20T18:31:00Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* What is the OWASP API Security Project? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the this project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202374</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202374"/>
				<updated>2015-10-20T18:30:15Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* November 2015 Meeting */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Santa_Barbara|extra=The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== November 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' '''6pm''' on Thursday, '''November 19th''', 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' TBA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:'''TBA&lt;br /&gt;
&lt;br /&gt;
'''Cost:''' Free!&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202373</id>
		<title>Santa Barbara</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Santa_Barbara&amp;diff=202373"/>
				<updated>2015-10-20T18:29:50Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Santa_Barbara|extra=The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix].&lt;br /&gt;
&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-santa_barbara|emailarchives=http://lists.owasp.org/pipermail/owasp-santa_barbara}} &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Upcoming Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== November 2015 Meeting ==&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, November 19th, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' AppFolio (new office): 90 Castilian Drive, Goleta, CA 93117&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' TBA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:'''TBA&lt;br /&gt;
&lt;br /&gt;
'''Cost:''' Free!&lt;br /&gt;
&lt;br /&gt;
=Previous Events=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''October 2015 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Thursday, October 8, 2015&lt;br /&gt;
&lt;br /&gt;
'''Where:''' Invoca Offices (upstairs) - 1025 Chapala Street Santa Barbara, CA 93101&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
'''April 2013 Meeting'''&lt;br /&gt;
&lt;br /&gt;
'''When:''' Monday, April 22th, from 5:00pm - 7:00pm&lt;br /&gt;
&lt;br /&gt;
'''Where:''' PayJunction , 11903 State St, Santa Barbara, CA&lt;br /&gt;
&lt;br /&gt;
'''Speaker #1:''' [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
'''Speaker #2:''' Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
'''Our Sponsor:''' PayJunction! &lt;br /&gt;
&lt;br /&gt;
'''Remote Webinar Link:'''  Not Recorded&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=Presentation Archives=&lt;br /&gt;
&lt;br /&gt;
The following presentations have been given at local chapter meetings: &lt;br /&gt;
&lt;br /&gt;
* April 2013 - [http://www.slideshare.net/jasonhaddix/pentesting-ios-applications Pentesting iOS Applications] by Jason Haddix&lt;br /&gt;
&lt;br /&gt;
* April 2013 -  Demo of the Newest Google XSS by Jimmy Mesta?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Events prior to this wiki layout are neither archived nor noted on this page.&lt;br /&gt;
&lt;br /&gt;
=SB OWASP Chapter Leaders=&lt;br /&gt;
&lt;br /&gt;
The chapter leaders are [mailto:david.shaw@owasp.org David Shaw] , [mailto:jimmy.mesta@owasp.org Jimmy Mesta], and [mailto:jason.haddix@owasp.org Jason Haddix]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:David_Shaw&amp;diff=202372</id>
		<title>User:David Shaw</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:David_Shaw&amp;diff=202372"/>
				<updated>2015-10-20T18:29:11Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* OWASP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP ==&lt;br /&gt;
David is an active member of several OWASP endeavors. Notable project involvements include:&lt;br /&gt;
&lt;br /&gt;
* '''Founder/Organizer''' of the [http://appseccalifornia.org OWASP AppSec California conference].&lt;br /&gt;
&lt;br /&gt;
* Chapter Founder (and current Chapter Leader) of '''[https://www.owasp.org/index.php/Santa_Barbara OWASP Santa Barbara]'''.&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_API_Security_Project OWASP API Security] '''Project Leader'''.&lt;br /&gt;
&lt;br /&gt;
== Bio ==&lt;br /&gt;
David has extensive experience in many aspects of information security.&lt;br /&gt;
&lt;br /&gt;
Beginning his career as a Network Security Analyst, David monitored perimeter firewalls and intrusion detection systems in order to identify and neutralize threats in real time. After working in the trenches of perimeter analysis, David joined an External Threat Assessment Team as a Security Researcher, working closely with large financial institutions to mitigate external risk and combat phishing attacks.&lt;br /&gt;
&lt;br /&gt;
In 2009, David joined Redspin and worked as a Senior Security Engineer, Director of Penetration Testing, and Senior Director of Engineering. David then led security assessment and software development teams as Redspin's Chief Technology Officer and VP of Professional Services, specializing in External and Application security assessments.&lt;br /&gt;
&lt;br /&gt;
David's current role is Chief Information Security Officer at AppFolio, where he is managing internal AppSec and SecOps.&lt;br /&gt;
&lt;br /&gt;
David has particular interests in complex threat modeling and unconventional attack vectors, and has been a speaker at ToorCon, LayerOne, DEF CON, NolaCon, THOTCON, BSides Las Vegas, BSides Los Angeles, and BSides Seattle.&lt;br /&gt;
&lt;br /&gt;
== Contact ==&lt;br /&gt;
&lt;br /&gt;
The easiest way to get in contact is to [mailto:david.shaw@owasp.org send an email].&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:David_Shaw&amp;diff=202371</id>
		<title>User:David Shaw</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:David_Shaw&amp;diff=202371"/>
				<updated>2015-10-20T18:27:47Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* OWASP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP ==&lt;br /&gt;
David is an active member of several OWASP endeavors. Notable project involvements include:&lt;br /&gt;
&lt;br /&gt;
* '''Founder/Organizer''' of the OWASP AppSec California conference&lt;br /&gt;
&lt;br /&gt;
* Chapter Founder (and current Chapter Leader) of '''OWASP Santa Barbara'''.&lt;br /&gt;
&lt;br /&gt;
* OWASP API Security '''Project Leader'''.&lt;br /&gt;
&lt;br /&gt;
== Bio ==&lt;br /&gt;
David has extensive experience in many aspects of information security.&lt;br /&gt;
&lt;br /&gt;
Beginning his career as a Network Security Analyst, David monitored perimeter firewalls and intrusion detection systems in order to identify and neutralize threats in real time. After working in the trenches of perimeter analysis, David joined an External Threat Assessment Team as a Security Researcher, working closely with large financial institutions to mitigate external risk and combat phishing attacks.&lt;br /&gt;
&lt;br /&gt;
In 2009, David joined Redspin and worked as a Senior Security Engineer, Director of Penetration Testing, and Senior Director of Engineering. David then led security assessment and software development teams as Redspin's Chief Technology Officer and VP of Professional Services, specializing in External and Application security assessments.&lt;br /&gt;
&lt;br /&gt;
David's current role is Chief Information Security Officer at AppFolio, where he is managing internal AppSec and SecOps.&lt;br /&gt;
&lt;br /&gt;
David has particular interests in complex threat modeling and unconventional attack vectors, and has been a speaker at ToorCon, LayerOne, DEF CON, NolaCon, THOTCON, BSides Las Vegas, BSides Los Angeles, and BSides Seattle.&lt;br /&gt;
&lt;br /&gt;
== Contact ==&lt;br /&gt;
&lt;br /&gt;
The easiest way to get in contact is to [mailto:david.shaw@owasp.org send an email].&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:David_Shaw&amp;diff=202370</id>
		<title>User:David Shaw</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:David_Shaw&amp;diff=202370"/>
				<updated>2015-10-20T18:27:14Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* OWASP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP ==&lt;br /&gt;
David is an active member of several OWASP endeavors. Notable project involvements include:&lt;br /&gt;
&lt;br /&gt;
* '''Founding organizer''' of the OWASP AppSec California conference&lt;br /&gt;
&lt;br /&gt;
* Chapter founder (and current chapter leader) of '''OWASP Santa Barbara'''.&lt;br /&gt;
&lt;br /&gt;
* OWASP API Security '''Project lead'''.&lt;br /&gt;
&lt;br /&gt;
== Bio ==&lt;br /&gt;
David has extensive experience in many aspects of information security.&lt;br /&gt;
&lt;br /&gt;
Beginning his career as a Network Security Analyst, David monitored perimeter firewalls and intrusion detection systems in order to identify and neutralize threats in real time. After working in the trenches of perimeter analysis, David joined an External Threat Assessment Team as a Security Researcher, working closely with large financial institutions to mitigate external risk and combat phishing attacks.&lt;br /&gt;
&lt;br /&gt;
In 2009, David joined Redspin and worked as a Senior Security Engineer, Director of Penetration Testing, and Senior Director of Engineering. David then led security assessment and software development teams as Redspin's Chief Technology Officer and VP of Professional Services, specializing in External and Application security assessments.&lt;br /&gt;
&lt;br /&gt;
David's current role is Chief Information Security Officer at AppFolio, where he is managing internal AppSec and SecOps.&lt;br /&gt;
&lt;br /&gt;
David has particular interests in complex threat modeling and unconventional attack vectors, and has been a speaker at ToorCon, LayerOne, DEF CON, NolaCon, THOTCON, BSides Las Vegas, BSides Los Angeles, and BSides Seattle.&lt;br /&gt;
&lt;br /&gt;
== Contact ==&lt;br /&gt;
&lt;br /&gt;
The easiest way to get in contact is to [mailto:david.shaw@owasp.org send an email].&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202369</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202369"/>
				<updated>2015-10-20T18:26:21Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* In Print */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202368</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202368"/>
				<updated>2015-10-20T18:25:14Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Openhub */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202367</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202367"/>
				<updated>2015-10-20T18:24:51Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: Undo revision 202315 by David Shaw (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Openhub ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.openhub.net/orgs/OWASP OWASP Project Openhub]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202366</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202366"/>
				<updated>2015-10-20T18:22:39Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Road Map and Getting Involved */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Security Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202365</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202365"/>
				<updated>2015-10-20T18:22:06Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Road Map and Getting Involved */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
'''Q4 2015 Priorities'''&lt;br /&gt;
* Establish the project, including mailing list, wiki page, etc.&lt;br /&gt;
* Conduct PR-related activities to involve the community at large.&lt;br /&gt;
* Conduct research to understand widely-accepted risks in APIs&lt;br /&gt;
* Compile Top Ten API Security Risks&lt;br /&gt;
&lt;br /&gt;
We'd love for you to get involved with this project if you feel you can contribute! Please contact the Project Leader to better understand how you can volunteer.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202364</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202364"/>
				<updated>2015-10-20T18:06:36Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Project About */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the primary wiki page to learn about this project.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202363</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202363"/>
				<updated>2015-10-20T18:06:13Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Project About */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202362</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202362"/>
				<updated>2015-10-20T18:05:36Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: Undo revision 202361 by David Shaw (talk)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202361</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202361"/>
				<updated>2015-10-20T18:04:32Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Project About */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202360</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202360"/>
				<updated>2015-10-20T18:02:07Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Contributors */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.&lt;br /&gt;
&lt;br /&gt;
The creator of this project and current Project Leader is [https://www.owasp.org/index.php/User:David_Shaw David Shaw].&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202359</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202359"/>
				<updated>2015-10-20T17:58:20Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* FAQs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
This project welcomes contributors of all sorts. The easiest way to get involved is to contact the Project Leader, and indicate that you're willing to help.&lt;br /&gt;
&lt;br /&gt;
==What type of contributors are you seeking?==&lt;br /&gt;
We're currently looking for software developers who have experience building out resilient APIs, and security assessors who have assessed APIs. This project is currently in the &amp;quot;research&amp;quot; stage, meaning that the more you can contribute to building out the project, the better!&lt;br /&gt;
&lt;br /&gt;
==Can I still participate if I'm not a developer/assessor?==&lt;br /&gt;
Sure -- we just need to figure out the correct role. If you're strong with technical writing, that would be great; if there are other skill sets you think you can bring to the table, please let us know.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202358</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202358"/>
				<updated>2015-10-20T17:53:30Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202357</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202357"/>
				<updated>2015-10-20T17:53:14Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
While working as developers or information security consulting, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.&lt;br /&gt;
&lt;br /&gt;
This project aims to create:&lt;br /&gt;
&lt;br /&gt;
* The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.&lt;br /&gt;
* Create a documentation portal for developers to build APIs in a secure manner.&lt;br /&gt;
* Work with the security community to maintain living documents that evolve with security trends.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202355</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202355"/>
				<updated>2015-10-20T16:53:11Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By helping developers create verifiably secure APIs, and helping security assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Breakers]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202354</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202354"/>
				<updated>2015-10-20T16:50:00Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* What is OWASP API Security Project? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By helping developers create verifiably secure APIs, and helping security assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is the OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202336</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202336"/>
				<updated>2015-10-19T23:41:46Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* OWASP API Security Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By helping developers create verifiably secure APIs, and helping security assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202335</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202335"/>
				<updated>2015-10-19T23:41:05Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* OWASP API Security Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
This project seeks to address the ever-increasing number of organizations that are deploying APIs as part of their software packages. These APIs are used both for internal tasks, and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By helping developers create verifiably secure APIs, and helping security assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202328</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202328"/>
				<updated>2015-10-19T19:40:55Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* OWASP API Security Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
More organizations than ever are creating and deploying web-based APIs. These APIs are used both for internal tasks, and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a '''documentation portal''' for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By helping developers create verifiably secure APIs, and helping security assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202327</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202327"/>
				<updated>2015-10-19T19:40:21Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* OWASP API Security Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
More organizations than ever are creating and deploying web-based APIs. These APIs are used both for internal tasks, and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a documentation portal for best practices when creating or assessing APIs.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By helping developers create verifiably secure APIs, and helping security assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202326</id>
		<title>OWASP API Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_API_Security_Project&amp;diff=202326"/>
				<updated>2015-10-19T19:38:40Z</updated>
		
		<summary type="html">&lt;p&gt;David Shaw: /* OWASP API Security Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP API Security Project==&lt;br /&gt;
&lt;br /&gt;
In today's increasingly programmatic world, many organizations employ public and private APIs. These APIs may be used for internal activities, or to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a '''Top 10 API Security Risks''' document, as well as a documentation portal for best practices.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By helping developers create verifiably secure APIs, and helping security assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
'''The OWASP API Security Project documents are free to use!&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP API Security Project? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
The OWASP API Security Project will be presented in 2016.&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:David_Shaw David Shaw]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[REST_Security_Cheat_Sheet]]&lt;br /&gt;
* [https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API Enterprise Security API]&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
Once API Security documents are created, they will be available for direct download here.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
There has not yet been press coverage of this project.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
There are no current print materials for this project.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;3&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The roadmap for this project is straightforward: we'll begin by conducting research and seeking feedback from developers and security auditors on the problems they most frequently encounter via web-based APIs. We'll create, from this research, the OWASP Top Ten API Risks, a sub-project of the API Security Project. Once this document is created (and maintained), we will also create guidelines in order to demonstrate each of the risks (as well as other, non-top-ten risks) and illustrate how to prevent them.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>David Shaw</name></author>	</entry>

	</feed>