[{"data":1,"prerenderedAt":102},["ShallowReactive",2],{"content-guides-api-gateway-governance-introduction":3},{"markdown":4,"frontMatterAttributes":5,"bodyRaw":14,"contributorPaths":15,"menuType":17,"contentName":18,"slug":19,"readingTime":20,"menu":21,"nextDocItem":30,"previousDocItem":101},"\u003Cp>Customers who build and deploy serverless APIs are looking to implement security controls for their API control and data planes. There are a number of approaches and tools to implement Amazon API Gateway security controls. This guide explains the options available in AWS and includes some example implementations.\u003C\u002Fp>\n\u003Cp>This guide focuses on Amazon API Gateway governance. For application level security controls, see the documentation and resources that are specific to the components and services used. For general serverless guidance, refer to \u003Ca href=\"https:\u002F\u002Fserverlessland.com\u002Fcontent\u002Fservice\u002Flambda\u002Fguides\u002Fgovernance\u002F1-introduction\">Implementing governance in depth for serverless applications\u003C\u002Fa>. \u003C\u002Fp>\n",{"title":6,"order":7,"authors":8,"callout":10},"Introduction",1,[9],"Giedrius Praspaliauskas",{"title":11,"description":12,"link":13},"Building an API platform on AWS","This guide summarizes the API lifecycle and provides an AWS point of view on building an API platform using Amazon API Gateway. It provides prescriptive guidance on 3rd party and AWS services to cover the end-to-end needs of the API lifecycle.","https:\u002F\u002Fserverlessland.com\u002Fcontent\u002Fservice\u002Fapi-gateway\u002Fpaved-path\u002Fbuilding-an-api-platform-on-aws\u002Fintroduction","Customers who build and deploy serverless APIs are looking to implement security controls for their API control and data planes. There are a number of approaches and tools to implement Amazon API Gateway security controls. This guide explains the options available in AWS and includes some example implementations.\n\nThis guide focuses on Amazon API Gateway governance. For application level security controls, see the documentation and resources that are specific to the components and services used. For general serverless guidance, refer to [Implementing governance in depth for serverless applications](https:\u002F\u002Fserverlessland.com\u002Fcontent\u002Fservice\u002Flambda\u002Fguides\u002Fgovernance\u002F1-introduction). \n\n",[16],"content\u002Fcontributors\u002Fgiedrius-praspaliauskas.json","LIST","Amazon API Gateway governance in depth","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Fintroduction","1 min",[22,57,86],{"title":23,"content":24},"Amazon API Gateway governance",[25,30,37,44,51],{"title":6,"order":7,"authors":26,"callout":27,"time":20,"path":28,"id":29,"link":19},[9],{"title":11,"description":12,"link":13},"introduction","introduction.md",{"title":31,"order":32,"time":33,"path":34,"id":35,"link":36},"Security controls",2,"2 min","controls","controls.md","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Fcontrols",{"title":38,"order":39,"time":40,"path":41,"id":42,"link":43},"Tools",3,"7 min","tools","tools.md","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Ftools",{"title":45,"order":46,"time":47,"path":48,"id":49,"link":50},"API management access control",4,"4 min","management_access","management_access.md","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Fmanagement_access",{"title":52,"order":53,"time":20,"path":54,"id":55,"link":56},"API management audit",5,"audit_track","audit_track.md","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Faudit_track",{"title":58,"content":59},"Use cases and examples",[60,66,73,80],{"title":61,"order":62,"time":20,"path":63,"id":64,"link":65},"Use-cases overview",6,"use_cases","use_cases.md","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Fuse_cases",{"title":67,"order":68,"time":69,"path":70,"id":71,"link":72},"Enforcing observability for governance",8,"3 min","observability","observability.md","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Fobservability",{"title":74,"order":75,"time":76,"path":77,"id":78,"link":79},"Enforcing security for governance",9,"5 min","access_control","access_control.md","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Faccess_control",{"title":81,"order":82,"time":47,"path":83,"id":84,"link":85},"Enforcing management control",10,"management","management.md","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Fmanagement",{"title":87,"content":88},"Summary",[89,95],{"title":90,"order":91,"time":20,"path":92,"id":93,"link":94},"Index of examples",11,"index","index.md","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Findex",{"title":96,"order":97,"time":20,"path":98,"id":99,"link":100},"Additional resources",12,"additional_resources","additional_resources.md","\u002Fcontent\u002Fguides\u002Fapi-gateway-governance\u002Fadditional_resources",null,1789814104017]