SV-274507r1143927_rule
V-274507
SRG-APP-000033
SRG-APP-000033-API-000070
CAT II
10
Build or configure the API to enforce access control using DOD-approved authorization mechanisms. Ensure that authorization decisions are dynamic and based on contextual factors (e.g., user role, device compliance, request attributes).
Update system documentation to reflect the authorization strategy and verify integration with access management and logging systems to meet Zero Trust Capability requirements.
Confirm that the API enforces access control using approved authorization methods, such as token-based mechanisms (e.g., OAuth 2.0, JWT), role-based access control (RBAC), attribute-based access control (ABAC), or policy-based decisions provided by a centralized authorization service.
Ensure the configuration aligns with DOD Zero Trust Reference Architecture Capability Authorization Enforcement, which requires that systems validate access requests using dynamic and contextual authorization decisions rather than relying solely on static permissions or network location.
Review system documentation, API gateway configurations, and authorization policies to verify that access control decisions are:
- Based on real-time evaluation of user identity, role, device posture, and other attributes.
- Applied consistently across all API endpoints.
- Logged for auditing and accountability.
If the API does not implement DOD-approved, context-aware authorization mechanisms as required under Zero Trust Capability or if authorization enforcement is not documented or configured, this is a finding.
V-274507
False
SRG-APP-000033-API-000070
Confirm that the API enforces access control using approved authorization methods, such as token-based mechanisms (e.g., OAuth 2.0, JWT), role-based access control (RBAC), attribute-based access control (ABAC), or policy-based decisions provided by a centralized authorization service.
Ensure the configuration aligns with DOD Zero Trust Reference Architecture Capability Authorization Enforcement, which requires that systems validate access requests using dynamic and contextual authorization decisions rather than relying solely on static permissions or network location.
Review system documentation, API gateway configurations, and authorization policies to verify that access control decisions are:
- Based on real-time evaluation of user identity, role, device posture, and other attributes.
- Applied consistently across all API endpoints.
- Logged for auditing and accountability.
If the API does not implement DOD-approved, context-aware authorization mechanisms as required under Zero Trust Capability or if authorization enforcement is not documented or configured, this is a finding.
M
5703