STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API Gateway must audit authentication and authorization information.

DISA Rule

SV-274527r1143553_rule

Vulnerability Number

V-274527

Group Title

SRG-APP-000095

Rule Version

SRG-APP-000095-API-001760

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API Gateway to log authentication and authorization events, including the appropriate level of detail (e.g., timestamps, user IDs, status codes).

Check Contents

If an API Gateway is not in use, this is Not Applicable.

Verify the API Gateway audits authentication and authorization information.

1. Confirm audit logging is enabled for authentication and authorization events. This includes both successful and failed authentication attempts, as well as the authorization decisions (e.g., whether a user is granted or denied access).

2. Verify the logs capture relevant authentication and authorization details.

3. After performing tests, review the logs for entries related to authentication and authorization. Ensure that logs contain the appropriate level of detail (e.g., timestamps, user IDs, status codes).

If the API Gateway does not audit authentication and authorization information, this is a finding.

Vulnerability Number

V-274527

Documentable

False

Rule Version

SRG-APP-000095-API-001760

Severity Override Guidance

If an API Gateway is not in use, this is Not Applicable.

Verify the API Gateway audits authentication and authorization information.

1. Confirm audit logging is enabled for authentication and authorization events. This includes both successful and failed authentication attempts, as well as the authorization decisions (e.g., whether a user is granted or denied access).

2. Verify the logs capture relevant authentication and authorization details.

3. After performing tests, review the logs for entries related to authentication and authorization. Ensure that logs contain the appropriate level of detail (e.g., timestamps, user IDs, status codes).

If the API Gateway does not audit authentication and authorization information, this is a finding.

Check Content Reference

M

Target Key

5703