APIs provide a foundation for innovation and digital transformation, but organizations struggle to secure their APIs, and API-related breaches are common. To fully address API security, pay attention to governance, discovery, testing, authentication and authorization, protection, detection, response, and your use of third-party APIs. This report equips security leaders with the key components of an API security program.