SV-274520r1143514_rule
V-274520
SRG-APP-000091
SRG-APP-000091-API-001730
CAT II
10
Build or configure the API to enable logging successful/unsuccessful attempts to access privileges.
Verify both successful and unsuccessful attempts to access privileges are configured to be logged. This may include user identity, timestamps, access attempts, and outcomes (success or failure).
Perform various test cases to simulate both successful and unsuccessful access.
After performing the test scenarios, access the logs generated by the API (or the centralized logging system) and check for entries related to authentication and authorization.
Cross-check the actual logging behavior with the organization’s auditing and security policies to verify the API meets required standards for logging successful and unsuccessful access attempts.
If the API does not generate audit records when successful/unsuccessful attempts to access privileges occur, this is a finding.
V-274520
False
SRG-APP-000091-API-001730
Verify both successful and unsuccessful attempts to access privileges are configured to be logged. This may include user identity, timestamps, access attempts, and outcomes (success or failure).
Perform various test cases to simulate both successful and unsuccessful access.
After performing the test scenarios, access the logs generated by the API (or the centralized logging system) and check for entries related to authentication and authorization.
Cross-check the actual logging behavior with the organization’s auditing and security policies to verify the API meets required standards for logging successful and unsuccessful access attempts.
If the API does not generate audit records when successful/unsuccessful attempts to access privileges occur, this is a finding.
M
5703