Student pricing is available for eligible university email holders. View plans

NextSprints
NextSprints Icon NextSprints Logo
Product Design

Master the art of designing products

Product Improvement

Identify scope for excellence

Product Success Metrics

Learn how to define success of product

Product Root Cause Analysis

Ace root cause problem solving

Product Trade-Off

Navigate trade-offs decisions like a pro

All Questions

Explore all questions

Meta (Facebook) PM Interview Course

Practice Meta-focused PM cases

Amazon PM Interview Course

Practice Amazon-focused PM cases

Apple PM Interview Course

Practice Apple-focused PM cases

Google PM Interview Course

Practice Google-focused PM cases

Microsoft PM Interview Course

Practice Microsoft-focused PM cases

All Courses

Explore all courses

1:1 PM Coaching

Practice in a one-to-one session

Resume Review

Narrate impactful stories via resume

Guides Pricing
nextsprints logo

Not a member?

By proceeding, you agree to our Terms of Use and confirm you have read our Privacy and Cookie Statement.

nextsprints logo

Register to continue.

Login with Google Login with LinkedIn

By proceeding, you agree to our Terms of Use and confirm you have read our Privacy and Cookie Statement .

Company focus

Kong
Product Improvement Hard Member-only

How might Kong enhance its plugin ecosystem to provide more robust security options for API authentication and authorization?

Prepared by NextSprints

15 mins
Report an error
Security Strategy Product Improvement Ecosystem Development API Management Cybersecurity Cloud Computing Authentication Plugin Ecosystem Kong API Security Authorization
Product Management Improvement Question: Enhancing Kong's API security plugin ecosystem

Introduction

Kong's plugin ecosystem is a critical component of its API gateway platform, providing essential functionality for API management, including security features. Enhancing the plugin ecosystem to offer more robust security options for API authentication and authorization is crucial in today's landscape of increasing cyber threats and complex API architectures. I'll outline a strategic approach to improve Kong's security plugins, focusing on user needs, market trends, and technical considerations.

Step 1

Clarifying Questions (5 mins)

  • Looking at Kong's position in the API management market, I'm thinking about the current security landscape and evolving threats. Could you share insights on the most pressing security challenges our customers are facing with their APIs?

Why it matters: Helps prioritize which security features to enhance or develop Expected answer: Increasing sophistication of attacks, need for fine-grained access control Impact on approach: Would focus on advanced authentication methods and granular authorization policies

  • Considering Kong's plugin architecture, I'm curious about the adoption rate of our existing security plugins. What percentage of our users are actively using our current authentication and authorization plugins, and which ones are most popular?

Why it matters: Indicates areas of strength and potential gaps in our security offerings Expected answer: 70% adoption, with JWT and OAuth2 being most popular Impact on approach: Would prioritize enhancing popular plugins while addressing underutilized but important security features

  • Given the rapid pace of change in the API security space, I'm wondering about our release cycle for security plugins. How frequently do we currently update our security plugins, and what's the process for incorporating new security standards or protocols?

Why it matters: Determines our agility in responding to new security threats and standards Expected answer: Quarterly major updates, with critical patches as needed Impact on approach: Would consider streamlining the release process for security plugins and establishing a rapid response system for emerging threats

  • Thinking about the broader API management ecosystem, I'm interested in understanding how our customers typically integrate Kong with other security tools or identity providers. What are the most common integration scenarios we're seeing?

Why it matters: Helps identify potential partnership opportunities and integration needs Expected answer: Frequent integrations with LDAP, Active Directory, and cloud identity providers Impact on approach: Would focus on improving interoperability and developing new plugins for popular third-party security tools

Tip

At this point, I'd like to take a 1-minute break to organize my thoughts before diving into the next step.

Subscribe to access the full answer

Image of author NextSprints

NextSprints

Updated Jan 22, 2025