
Customers who build and deploy serverless APIs are looking to implement security controls for their API control and data planes. There are a number of approaches and tools to implement Amazon API Gateway security controls. This guide explains the options available in AWS and includes some example implementations.
This guide focuses on Amazon API Gateway governance. For application level security controls, see the documentation and resources that are specific to the components and services used. For general serverless guidance, refer to Implementing governance in depth for serverless applications.