API security governance: One of the key tenets of enabling defense-in-depth security practices within an enterprise is separation of concerns. It requires support for separation of duties between the service providers (the IT architect, IT security, and business) and API service consumers (developers and end users).