SV-274527r1143553_rule
V-274527
SRG-APP-000095
SRG-APP-000095-API-001760
CAT II
10
Build or configure the API Gateway to log authentication and authorization events, including the appropriate level of detail (e.g., timestamps, user IDs, status codes).
If an API Gateway is not in use, this is Not Applicable.
Verify the API Gateway audits authentication and authorization information.
1. Confirm audit logging is enabled for authentication and authorization events. This includes both successful and failed authentication attempts, as well as the authorization decisions (e.g., whether a user is granted or denied access).
2. Verify the logs capture relevant authentication and authorization details.
3. After performing tests, review the logs for entries related to authentication and authorization. Ensure that logs contain the appropriate level of detail (e.g., timestamps, user IDs, status codes).
If the API Gateway does not audit authentication and authorization information, this is a finding.
V-274527
False
SRG-APP-000095-API-001760
If an API Gateway is not in use, this is Not Applicable.
Verify the API Gateway audits authentication and authorization information.
1. Confirm audit logging is enabled for authentication and authorization events. This includes both successful and failed authentication attempts, as well as the authorization decisions (e.g., whether a user is granted or denied access).
2. Verify the logs capture relevant authentication and authorization details.
3. After performing tests, review the logs for entries related to authentication and authorization. Ensure that logs contain the appropriate level of detail (e.g., timestamps, user IDs, status codes).
If the API Gateway does not audit authentication and authorization information, this is a finding.
M
5703