STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API Gateway must generate audit records when successful/unsuccessful attempts to access privileges occur.

DISA Rule

SV-274519r1143513_rule

Vulnerability Number

V-274519

Group Title

SRG-APP-000091

Rule Version

SRG-APP-000091-API-001725

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API Gateway to enable logging successful/unsuccessful attempts to access privileges.

Check Contents

If an API Gateway is not in use, this is Not Applicable.

Verify both successful and unsuccessful attempts to access privileges are configured to be logged. This may include user identity, timestamps, access attempts, and outcomes (success or failure).

Perform various test cases to simulate both successful and unsuccessful access.

After performing the test scenarios, access the logs generated by the API Gateway (or the centralized logging system) and check for entries related to authentication and authorization.

Cross-check the actual logging behavior with the organization’s auditing and security policies to verify the API Gateway meets required standards for logging successful and unsuccessful access attempts.

If the API Gateway does not generate audit records when successful/unsuccessful attempts to access privileges occur, this is a finding.

Vulnerability Number

V-274519

Documentable

False

Rule Version

SRG-APP-000091-API-001725

Severity Override Guidance

If an API Gateway is not in use, this is Not Applicable.

Verify both successful and unsuccessful attempts to access privileges are configured to be logged. This may include user identity, timestamps, access attempts, and outcomes (success or failure).

Perform various test cases to simulate both successful and unsuccessful access.

After performing the test scenarios, access the logs generated by the API Gateway (or the centralized logging system) and check for entries related to authentication and authorization.

Cross-check the actual logging behavior with the organization’s auditing and security policies to verify the API Gateway meets required standards for logging successful and unsuccessful access attempts.

If the API Gateway does not generate audit records when successful/unsuccessful attempts to access privileges occur, this is a finding.

Check Content Reference

M

Target Key

5703