39% of Azure Security Benchmark you already have
OWASP API Security Top 10 already covers about 39% of Azure Security Benchmark, leaving
33 of 54 controls as genuinely new work.
Already covered 0
Likely covered 21
New work 33
No control in OWASP API Security Top 10
maps directly to one in Azure Security Benchmark. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in OWASP API Security Top 10 reaches these. This is the list to scope.
AM-2Use Only Approved Services
AM-3Ensure Security of Asset Lifecycle Management
ASB-09Federation and single sign-on
ASB-10API security and access tokens
ASB-15Secure data deletion in cloud
ASB-18Cloud workload protection
ASB-25Service level agreement management
BR-1Ensure Regular Automated Backups
BR-2Protect Backup and Recovery Data
DP-2Monitor Anomalies and Threats Targeting Sensitive Data
DP-3Encrypt Sensitive Data in Transit
DP-4Encrypt Data at Rest by Default
DS-6Enforce Security of Workload Throughout DevOps Lifecycle
ES-1Use Endpoint Detection and Response (EDR)
ES-2Use Modern Anti-Malware Software
GS-1Align Organisation Roles, Responsibilities and Accountabilities
IM-1Use Centralised Identity and Authentication System
IM-3Manage Application Identities Securely
IM-4Authenticate Server and Services
IM-6Use Strong Authentication Controls
IM-7Restrict Resource Access Based on Conditions
LT-3Enable Logging for Investigation
LT-4Enable Network Logging for Investigation
LT-5Centralise Security Log Management and Analysis
NS-1Establish Network Segmentation Boundaries
NS-2Secure Cloud Services with Network Controls
NS-3Deploy Firewall at Edge of Enterprise Network
NS-5Deploy DDoS Protection
PA-1Separate and Limit Highly Privileged Users
PA-2Avoid Standing Access for User Accounts and Permissions
PA-3Manage Lifecycle of Identities and Entitlements
PV-2Audit and Enforce Secure Configurations
PV-5Perform Vulnerability Assessments
Show the 21 you already have
ASB-01Shared responsibility model definition
ASB-02Cloud security policy and strategy
ASB-03Cloud risk assessment
ASB-04Regulatory compliance for cloud services
ASB-05Cloud security roles and responsibilities
ASB-06Cloud identity management
ASB-07Multi-factor authentication for cloud
ASB-08Privileged access in cloud environments
ASB-11Data classification for cloud
ASB-12Encryption of cloud-stored data
ASB-13Data residency and sovereignty
ASB-14Data backup and recovery in cloud
ASB-16Virtual network segmentation
ASB-17Container and serverless security
ASB-19Image and template hardening
ASB-20Cloud configuration management
ASB-21Cloud security monitoring and logging
ASB-22Incident response in cloud
ASB-23Cloud vulnerability management
ASB-24Cloud change management
DS-2Ensure Inventory of Software Components in Code
How this is calculated
Already covered means a mapping runs from a control in OWASP API Security Top 10 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition