API Security Risk Assessment Checklist Form
Assess the security posture of an API by reviewing core controls, identifying risks, and recording remediation priorities.
API Context
API Name
*
API Base URL or Endpoint
*
Environment Being Assessed
*
Production
Staging
Development
Other
API Owner / Team
*
Security Risk Checklist
Key API Security Concerns
*
Authentication present
Authorization enforced
Rate limiting enabled
Input validation in place
Encrypted transport enabled
Secrets not exposed in responses
Logging and monitoring enabled
Error messages not overly verbose
Versioning strategy defined
Dependency updates reviewed
Other
Authentication controls reviewed
API key authentication
OAuth 2.0
JWT-based authentication
Mutual TLS
Other
Authorization checks enforced
Role-based access control
Scope-based access control
Object-level authorization
Field-level authorization
Other
Traffic throttling in place
Per-user rate limiting
Per-IP rate limiting
Burst protection
Quota enforcement
Other
Request data validation
Schema validation
Type validation
Length validation
Allowlist validation
Other
Transport protection
TLS 1.2 or higher
TLS 1.3
HSTS enforced
Secure certificates managed
Other
Secrets handling review
No secrets in responses
No secrets in logs
Secrets stored securely
Secret rotation defined
Other
Operational visibility
Access logging enabled
Security event monitoring
Alerting configured
Audit trails retained
Other
Error handling quality
Generic error messages
No stack traces exposed
No internal identifiers exposed
Consistent error format
Other
Maintenance and release hygiene
API versioning strategy defined
Dependency updates reviewed
Known vulnerabilities assessed
Patch cadence established
Other
Assessment Ratings
Overall Security Posture
*
Very Weak
1
2
3
4
5
6
7
8
9
Very Strong
10
1 is Very Weak, 10 is Very Strong
Likelihood of Exploitation
*
Very Unlikely
1
2
3
4
5
6
7
8
9
Very Likely
10
1 is Very Unlikely, 10 is Very Likely
Current Risk Level
*
Low
Medium
High
Critical
Findings and Next Steps
Notable Findings
*
Recommended Remediation Actions
*
Follow-up Priority
*
Immediate
Within 7 days
Within 30 days
Planned
Additional Notes
Submit Assessment
Should be Empty: