STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must generate audit records of what type of events occurred.

DISA Rule

SV-274524r1143517_rule

Vulnerability Number

V-274524

Group Title

SRG-APP-000095

Rule Version

SRG-APP-000095-API-001745

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to audit what type of events occurred.

Check Contents

Verify the API generates audit records of what type of events occurred.

1. Inspect the API’s configuration settings and verify logging is enabled and audit records are being generated for key events such as authentication, authorization, data access, and errors.

2. Make a valid API request and verify successful events are logged.

3. Simulate system errors under specific conditions (e.g., database unavailability, timeout errors, internal exceptions).

4. Check the audit or access logs in the API or logging platform (e.g., AWS CloudWatch, Splunk, ELK stack). Verify that the logs contain entries for the triggered events.

5. Inspect the log entries for the following:
- Event Type: Look for the event’s description or category (e.g., authentication attempt, data access, system error).

If the API does not generate audit records for the type of event, this is a finding.

Vulnerability Number

V-274524

Documentable

False

Rule Version

SRG-APP-000095-API-001745

Severity Override Guidance

Verify the API generates audit records of what type of events occurred.

1. Inspect the API’s configuration settings and verify logging is enabled and audit records are being generated for key events such as authentication, authorization, data access, and errors.

2. Make a valid API request and verify successful events are logged.

3. Simulate system errors under specific conditions (e.g., database unavailability, timeout errors, internal exceptions).

4. Check the audit or access logs in the API or logging platform (e.g., AWS CloudWatch, Splunk, ELK stack). Verify that the logs contain entries for the triggered events.

5. Inspect the log entries for the following:
- Event Type: Look for the event’s description or category (e.g., authentication attempt, data access, system error).

If the API does not generate audit records for the type of event, this is a finding.

Check Content Reference

M

Target Key

5703