SlideShare a Scribd company logo
All contents © MuleSoft, LLC
Zero Trust Security
for your APIs
By Akshata Sawant, Developer
Advocate at MuleSoft
@sawantakshata02
/akshata-sawant-192a3a121
About Me
● Developer Advocate at MuleSoft
● 5+ yrs - MuleSoft, APIs & Integrations
● Author and blogger
● Love travelling & photography
● Big time foodie! <3
@sawantakshata02
/akshata-sawant-192a3a121
Agenda
● Need for API Security
● What is Zero Trust Security(ZTS)
● How to implement
ZTS for your APIs
● QnA
Forward-looking statements
This presentation contains forward-looking statements about the Company’s financial and operating results, which may include expected GAAP and non-GAAP
financial and other operating and non-operating results, including revenue, net income, earnings per share, operating cash flow growth, operating margin
improvement, expected revenue growth, expected current remaining performance obligation growth, expected tax rates, stock-based compensation expenses,
amortization of purchased intangibles, shares outstanding, market growth, environmental, social and governance goals, expected capital allocation, including
mergers and acquisitions, capital expenditures and other investments, expectations regarding closing contemplated acquisitions and contributions from acquired
companies. The achievement or success of the matters covered by such forward-looking statements involves risks, uncertainties and assumptions. If any such
risks or uncertainties materialize or if any of the assumptions prove incorrect, the Company’s results could differ materially from the results expressed or implied
by the forward-looking statements it makes. The risks and uncertainties referred to above include those factors discussed in Salesforce’s reports filed from time
to time with the Securities and Exchange Commission, including, but not limited to: risks associated with our ability to successfully integrate Slack Technologies,
Inc.’s operations; our ability to realize the anticipated benefits of the Slack Technologies, Inc. transaction; the impact of Slack Technologies, Inc.’s business model
on our ability to forecast revenue results; disruption from the transaction making it more difficult to maintain business and operational relationships; the impact of,
and actions we may take in response to, the COVID-19 pandemic, related public health measures and resulting economic downturn and market volatility; our
ability to maintain service performance and security levels meeting the expectations of our customers, and the resources and costs required to avoid
unanticipated downtime and prevent, detect and remediate performance degradation and security breaches; our ability to secure and costs related to data center
capacity and other infrastructure provided by third parties; our reliance on third-party hardware, software and platform providers; the effect of evolving domestic
and foreign government regulations, including those related to the provision of services on the Internet, those related to accessing the Internet, and those
addressing data privacy; current and potential litigation involving us or our industry, including litigation involving acquired entities such as Tableau; regulatory
developments and regulatory investigations involving us or affecting our industry; our ability to successfully introduce new services and product features, including
any efforts to expand our services beyond the CRM market; the success of our strategy of acquiring or making investments in complementary businesses and
strategic partnerships; our ability to compete in the market in which we participate; the success of our business strategy and our plan to build our business; our
ability to execute our business plans; our ability to continue to grow unearned revenue and remaining performance obligation; the pace of change and innovation
in enterprise cloud computing services; the seasonal nature of our sales cycles; our ability to limit customer attrition and costs related to those efforts; the success
of our international expansion strategy; the demands on our personnel and infrastructure resulting from significant growth in our customer base and operations;
our dependency on the development and maintenance of the infrastructure of the Internet; our real estate and office facilities strategy and related costs and
uncertainties; fluctuations in, and our ability to predict, our operating results and cash flows; the variability in our results arising from the accounting for term
license revenue products; the performance and fair value of our investments in complementary businesses through our strategic investment portfolio; our ability to
protect our intellectual property rights; our ability to develop our brands; the valuation of our deferred tax assets and the release of related valuation allowances;
uncertainties regarding our tax obligations in connection with potential jurisdictional transfers of intellectual property; uncertainties regarding the effect of general
economic conditions; and risks related to our debt and lease obligations.
API Security is a major concern
41%
of organizations
suffered API Security
issues in the last year
JML
Servers
Clients
(Users & Apps)
API
Any GTA
fans here?
Zero Trust Security
Never trust; always verify
Never Trust;
Always Verify
Least Privilege
and Default Deny
Full Visibility
and Inspection
Centralized
Management
How to achieve ZTS for your APIs?
Layered security approach
Tools-in-action
Process
layer
Experience
layer
System
layer
Illustrative
Order Management system
Rate-Limiting
CORS
Basic Auth- LDAP
Header-injection
Rate-limiting
JWT
Basic
Authentication
Header Injection
CORS
OAuth MFA
Basic-Authentication
Header Removal
JWT Policy
Custom Policy
Rate-limiting
SLA Based
Process
layer
Experience
layer
System
layer
Illustrative
Layered security with API-led connectivity
Line 1
Line 2
Basic Auth- LDAP
Line 1
Line 2
Line 1
Line 2
JWT
Line 1
Line 2
Line 1
Line 2
OAuth MFA
Line 1
Line 2
Line 1
Line 2
JWT
Line 1
Line 2
Unlock and unify data anywhere
Integrate systems wherever they reside — on-
premises, cloud, or hybrid
Securely empower your
business with APIs
Allow API discovery and reuse with centralized
management and governance
Create seamless digital experiences,
faster
Easily apply proven assets and best practices
from an API and integration marketplace
MuleSoft Anypoint Platform
World’s #1 integration and API platform
Source: MuleSoft customer case studies
3x
faster
with reuse vs.
custom code
14
Universal API Management on Anypoint Platform
Build new APIs from
scratch
Manage APIs to consistent
quality and security
Maxie
API developer
Dan
API owner
15
Demo 1: Build APIs following security standards
Build new APIs from
scratch
Maxie
API developer
❖ Build API Specification (Design first!)
❖ Catalog APIs from existing repository
❖ Implement and test business logic
❖ Deploy application & monitor performance
Let us head over
to Anypoint
Platform
18
Demo 1: Build APIs following security standards
Build new APIs from
scratch
Maxie
API developer
19
2: Manage and Secure APIs
Manage APIs to consistent
quality and security
Dan
API owner
❖ Proxy APIs built by developers
❖ Add security & SLA policies
❖ Manage & approve contracts
❖ Monitor services & diagnose issues
❖ Ensure specifications conform to governance standards
Let us head over
to Anypoint
Platform
Security and governance by default
Start with a secure foundation
Build on a platform with ISO 27001, SOC 1 & 2,
HIPAA, PCI DSS and GDPR compliance
Protect your deployment environments
Enforce threat protection at each edge perimeter
automatically using Anypoint Security
Secure each service consistently
Secure and manage any individual API, groups of
APIs, or Kubernetes based microservices with API
Manager and Anypoint Service Mesh
Follow a zero-trust model by applying security in layers
● Need for API Security
● What is zero trust security
● MuleSoft Anypoint Platform and it’s capabilities
● How to apply policies and achieve layered security
Key Takeaways
Next Steps
https://www.mulesoft.com
Join the
Community
Watch us
on LIVE on Twitch
Try Anypoint
Platform for free
Available on amazon.com and Packt Publication
MuleSoft for
Salesforce Developers
Amazon: https://amzn.to/3KeI5kX
QnA?
You can also reach out to us on for further queries
https://www.mulesoft.com
@sawantakshata02
/akshata-sawant-192a3a121
Thank you

More Related Content

PPTX
[Madrid-Meetup April 22] UAPIM.pptx
PDF
DC MuleSoft Meetup: TDX Talk: API Security The 3 Keys To Protect Your Digital...
PDF
INTERFACE, by apidays - The future of API Management in a hybrid, multi-clou...
PDF
Perth Meetup December 2021
PPTX
Denver MuleSoft Meetup: TDX Talk - Automatically Secure and Manage any API at...
PDF
Nonprofit User Group.pdf
PDF
Princeton MuleSoft - Meetup MuleSoft IDP
PPTX
Summer-22-FG-Mai-2022
[Madrid-Meetup April 22] UAPIM.pptx
DC MuleSoft Meetup: TDX Talk: API Security The 3 Keys To Protect Your Digital...
INTERFACE, by apidays - The future of API Management in a hybrid, multi-clou...
Perth Meetup December 2021
Denver MuleSoft Meetup: TDX Talk - Automatically Secure and Manage any API at...
Nonprofit User Group.pdf
Princeton MuleSoft - Meetup MuleSoft IDP
Summer-22-FG-Mai-2022

Similar to Zero Trust Security - Updated (20)

PPTX
MuleSoft + AI + IDP + ACB | MuleSoft Mysore Meetup #50
PDF
Jaipur MuleSoft Meetup No. 3
PDF
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
PDF
Architecting Integrations for Observability.pdf
PPTX
Implementing Einstein OCR
PDF
Sample Gallery: Reference Code and Best Practices for Salesforce Developers
PDF
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
PDF
WT19: Platform Events Are for Admins Too!
PPTX
Dreamforce 2019: "Using Quip for Better Documentation of your Salesforce Org"
PDF
Let's Learn About Heroku and How to Integrate with Salesforce
PDF
Alba Rivas - Building Slack Applications with Bolt.js.pdf
PDF
TDX Global Gathering - Wellington UG
PPTX
Release Winter 22 FR
PPTX
Winter 22 release
PDF
Real-time Salesforce1 Dashboards with Raspberry-pi & Heroku
PDF
Admin Best Practices: Introducing Einstein Recommendation Builder
PPTX
Anypoint_Code_Builder_-Toronto Meetup.pptx
PDF
tdx20cosenhancingyourcrmwitheinsteinai1592951856546.pdf
PPTX
MuleSoft Composer - OKC Oklahoma City MuleSoft Meetup 11/11/21
PPTX
Summer '20 preview release overview-deck
MuleSoft + AI + IDP + ACB | MuleSoft Mysore Meetup #50
Jaipur MuleSoft Meetup No. 3
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
Architecting Integrations for Observability.pdf
Implementing Einstein OCR
Sample Gallery: Reference Code and Best Practices for Salesforce Developers
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
WT19: Platform Events Are for Admins Too!
Dreamforce 2019: "Using Quip for Better Documentation of your Salesforce Org"
Let's Learn About Heroku and How to Integrate with Salesforce
Alba Rivas - Building Slack Applications with Bolt.js.pdf
TDX Global Gathering - Wellington UG
Release Winter 22 FR
Winter 22 release
Real-time Salesforce1 Dashboards with Raspberry-pi & Heroku
Admin Best Practices: Introducing Einstein Recommendation Builder
Anypoint_Code_Builder_-Toronto Meetup.pptx
tdx20cosenhancingyourcrmwitheinsteinai1592951856546.pdf
MuleSoft Composer - OKC Oklahoma City MuleSoft Meetup 11/11/21
Summer '20 preview release overview-deck
Ad

More from Akshata Sawant (20)

PPTX
Robust Data Cloud Protection with MuleSoft-2.pptx
PPTX
Anypoint Tools and MuleSoft Automation (DRAFT).pptx
PPTX
London MuleSoft Meetup
PPTX
Mumbai MuleSoft Meetup #22.pptx
PPTX
Mumbai MuleSoft Meetup #21
PPTX
Manchester MuleSoft Meetup #8 - 28 Sept.pptx
PPTX
London MuleSoft Meetup 15 Sept
PPTX
Manchester MuleSoft Meetup #7
PPTX
Zero Trust Security in practice.pptx
PPTX
Mumbai MuleSoft Meetup #20
PPTX
Power of Einstein Analytics - Salesforce + Mulesoft
PPTX
Mumbai MuleSoft Meetup #19 - Anypoint monitoring and MQ Integrations
PPTX
Manchester MuleSoft Meetup #6 - Runtime Fabric with Mulesoft
PPTX
Mumbai MuleSoft Meetup #18
PPTX
Mumbai MuleSoft Meetup #17 - GraphQL
PPTX
Mumbai MuleSoft Meetup #15
PPTX
Mumbai MuleSoft Meetup 13
PPTX
Mumbai MuleSoft Meetup 12
PPTX
Mumbai MuleSoft Meetup 11
PPTX
Meet up slides_mumbai_05022020_final
Robust Data Cloud Protection with MuleSoft-2.pptx
Anypoint Tools and MuleSoft Automation (DRAFT).pptx
London MuleSoft Meetup
Mumbai MuleSoft Meetup #22.pptx
Mumbai MuleSoft Meetup #21
Manchester MuleSoft Meetup #8 - 28 Sept.pptx
London MuleSoft Meetup 15 Sept
Manchester MuleSoft Meetup #7
Zero Trust Security in practice.pptx
Mumbai MuleSoft Meetup #20
Power of Einstein Analytics - Salesforce + Mulesoft
Mumbai MuleSoft Meetup #19 - Anypoint monitoring and MQ Integrations
Manchester MuleSoft Meetup #6 - Runtime Fabric with Mulesoft
Mumbai MuleSoft Meetup #18
Mumbai MuleSoft Meetup #17 - GraphQL
Mumbai MuleSoft Meetup #15
Mumbai MuleSoft Meetup 13
Mumbai MuleSoft Meetup 12
Mumbai MuleSoft Meetup 11
Meet up slides_mumbai_05022020_final
Ad

Recently uploaded (20)

PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Electronic commerce courselecture one. Pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
cuic standard and advanced reporting.pdf
PDF
Machine learning based COVID-19 study performance prediction
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Approach and Philosophy of On baking technology
PDF
Modernizing your data center with Dell and AMD
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
Encapsulation_ Review paper, used for researhc scholars
Electronic commerce courselecture one. Pdf
20250228 LYD VKU AI Blended-Learning.pptx
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Agricultural_Statistics_at_a_Glance_2022_0.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
cuic standard and advanced reporting.pdf
Machine learning based COVID-19 study performance prediction
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Digital-Transformation-Roadmap-for-Companies.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Dropbox Q2 2025 Financial Results & Investor Presentation
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Approach and Philosophy of On baking technology
Modernizing your data center with Dell and AMD
Diabetes mellitus diagnosis method based random forest with bat algorithm
Understanding_Digital_Forensics_Presentation.pptx
The Rise and Fall of 3GPP – Time for a Sabbatical?

Zero Trust Security - Updated

  • 1. All contents © MuleSoft, LLC Zero Trust Security for your APIs By Akshata Sawant, Developer Advocate at MuleSoft @sawantakshata02 /akshata-sawant-192a3a121
  • 2. About Me ● Developer Advocate at MuleSoft ● 5+ yrs - MuleSoft, APIs & Integrations ● Author and blogger ● Love travelling & photography ● Big time foodie! <3 @sawantakshata02 /akshata-sawant-192a3a121
  • 3. Agenda ● Need for API Security ● What is Zero Trust Security(ZTS) ● How to implement ZTS for your APIs ● QnA
  • 4. Forward-looking statements This presentation contains forward-looking statements about the Company’s financial and operating results, which may include expected GAAP and non-GAAP financial and other operating and non-operating results, including revenue, net income, earnings per share, operating cash flow growth, operating margin improvement, expected revenue growth, expected current remaining performance obligation growth, expected tax rates, stock-based compensation expenses, amortization of purchased intangibles, shares outstanding, market growth, environmental, social and governance goals, expected capital allocation, including mergers and acquisitions, capital expenditures and other investments, expectations regarding closing contemplated acquisitions and contributions from acquired companies. The achievement or success of the matters covered by such forward-looking statements involves risks, uncertainties and assumptions. If any such risks or uncertainties materialize or if any of the assumptions prove incorrect, the Company’s results could differ materially from the results expressed or implied by the forward-looking statements it makes. The risks and uncertainties referred to above include those factors discussed in Salesforce’s reports filed from time to time with the Securities and Exchange Commission, including, but not limited to: risks associated with our ability to successfully integrate Slack Technologies, Inc.’s operations; our ability to realize the anticipated benefits of the Slack Technologies, Inc. transaction; the impact of Slack Technologies, Inc.’s business model on our ability to forecast revenue results; disruption from the transaction making it more difficult to maintain business and operational relationships; the impact of, and actions we may take in response to, the COVID-19 pandemic, related public health measures and resulting economic downturn and market volatility; our ability to maintain service performance and security levels meeting the expectations of our customers, and the resources and costs required to avoid unanticipated downtime and prevent, detect and remediate performance degradation and security breaches; our ability to secure and costs related to data center capacity and other infrastructure provided by third parties; our reliance on third-party hardware, software and platform providers; the effect of evolving domestic and foreign government regulations, including those related to the provision of services on the Internet, those related to accessing the Internet, and those addressing data privacy; current and potential litigation involving us or our industry, including litigation involving acquired entities such as Tableau; regulatory developments and regulatory investigations involving us or affecting our industry; our ability to successfully introduce new services and product features, including any efforts to expand our services beyond the CRM market; the success of our strategy of acquiring or making investments in complementary businesses and strategic partnerships; our ability to compete in the market in which we participate; the success of our business strategy and our plan to build our business; our ability to execute our business plans; our ability to continue to grow unearned revenue and remaining performance obligation; the pace of change and innovation in enterprise cloud computing services; the seasonal nature of our sales cycles; our ability to limit customer attrition and costs related to those efforts; the success of our international expansion strategy; the demands on our personnel and infrastructure resulting from significant growth in our customer base and operations; our dependency on the development and maintenance of the infrastructure of the Internet; our real estate and office facilities strategy and related costs and uncertainties; fluctuations in, and our ability to predict, our operating results and cash flows; the variability in our results arising from the accounting for term license revenue products; the performance and fair value of our investments in complementary businesses through our strategic investment portfolio; our ability to protect our intellectual property rights; our ability to develop our brands; the valuation of our deferred tax assets and the release of related valuation allowances; uncertainties regarding our tax obligations in connection with potential jurisdictional transfers of intellectual property; uncertainties regarding the effect of general economic conditions; and risks related to our debt and lease obligations.
  • 5. API Security is a major concern 41% of organizations suffered API Security issues in the last year JML Servers Clients (Users & Apps) API
  • 7. Zero Trust Security Never trust; always verify Never Trust; Always Verify Least Privilege and Default Deny Full Visibility and Inspection Centralized Management
  • 8. How to achieve ZTS for your APIs? Layered security approach
  • 10. Process layer Experience layer System layer Illustrative Order Management system Rate-Limiting CORS Basic Auth- LDAP Header-injection Rate-limiting JWT Basic Authentication Header Injection CORS OAuth MFA Basic-Authentication Header Removal JWT Policy Custom Policy Rate-limiting SLA Based
  • 11. Process layer Experience layer System layer Illustrative Layered security with API-led connectivity Line 1 Line 2 Basic Auth- LDAP Line 1 Line 2 Line 1 Line 2 JWT Line 1 Line 2 Line 1 Line 2 OAuth MFA Line 1 Line 2 Line 1 Line 2 JWT Line 1 Line 2
  • 12. Unlock and unify data anywhere Integrate systems wherever they reside — on- premises, cloud, or hybrid Securely empower your business with APIs Allow API discovery and reuse with centralized management and governance Create seamless digital experiences, faster Easily apply proven assets and best practices from an API and integration marketplace MuleSoft Anypoint Platform World’s #1 integration and API platform Source: MuleSoft customer case studies 3x faster with reuse vs. custom code
  • 13. 14 Universal API Management on Anypoint Platform Build new APIs from scratch Manage APIs to consistent quality and security Maxie API developer Dan API owner
  • 14. 15 Demo 1: Build APIs following security standards Build new APIs from scratch Maxie API developer ❖ Build API Specification (Design first!) ❖ Catalog APIs from existing repository ❖ Implement and test business logic ❖ Deploy application & monitor performance
  • 15. Let us head over to Anypoint Platform
  • 16. 18 Demo 1: Build APIs following security standards Build new APIs from scratch Maxie API developer
  • 17. 19 2: Manage and Secure APIs Manage APIs to consistent quality and security Dan API owner ❖ Proxy APIs built by developers ❖ Add security & SLA policies ❖ Manage & approve contracts ❖ Monitor services & diagnose issues ❖ Ensure specifications conform to governance standards
  • 18. Let us head over to Anypoint Platform
  • 19. Security and governance by default Start with a secure foundation Build on a platform with ISO 27001, SOC 1 & 2, HIPAA, PCI DSS and GDPR compliance Protect your deployment environments Enforce threat protection at each edge perimeter automatically using Anypoint Security Secure each service consistently Secure and manage any individual API, groups of APIs, or Kubernetes based microservices with API Manager and Anypoint Service Mesh Follow a zero-trust model by applying security in layers
  • 20. ● Need for API Security ● What is zero trust security ● MuleSoft Anypoint Platform and it’s capabilities ● How to apply policies and achieve layered security Key Takeaways
  • 21. Next Steps https://www.mulesoft.com Join the Community Watch us on LIVE on Twitch Try Anypoint Platform for free
  • 22. Available on amazon.com and Packt Publication MuleSoft for Salesforce Developers Amazon: https://amzn.to/3KeI5kX
  • 23. QnA? You can also reach out to us on for further queries https://www.mulesoft.com @sawantakshata02 /akshata-sawant-192a3a121