STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must encrypt data in transit.

DISA Rule

SV-274497r1142303_rule

Vulnerability Number

V-274497

Group Title

SRG-APP-000014

Rule Version

SRG-APP-000014-API-000020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API server to automatically redirect any HTTP request to HTTPS. This ensures all communication with the API is encrypted by default.

Check Contents

API must verify sensitive tokens are transmitted over secure channels using HTTPS. This includes both internal and user-specific tokens.

If data being transmitted between the client and server is not using HTTPS, this is a finding.

Vulnerability Number

V-274497

Documentable

False

Rule Version

SRG-APP-000014-API-000020

Severity Override Guidance

API must verify sensitive tokens are transmitted over secure channels using HTTPS. This includes both internal and user-specific tokens.

If data being transmitted between the client and server is not using HTTPS, this is a finding.

Check Content Reference

M

Target Key

5703