SV-274528r1143554_rule
V-274528
SRG-APP-000095
SRG-APP-000095-API-001765
CAT II
10
Build or configure the API to log authentication and authorization events, including the appropriate level of detail (e.g., timestamps, user IDs, status codes).
Verify the API generates audit records of what type of events occurred.
1. Confirm audit logging is enabled for authentication and authorization events. This includes both successful and failed authentication attempts, as well as the authorization decisions (e.g., whether a user is granted or denied access).
2. Verify the logs capture relevant authentication and authorization details.
3. After performing tests, review the logs for entries related to authentication and authorization. Ensure that logs contain the appropriate level of detail (e.g., timestamps, user IDs, status codes).
If the API does not audit authentication and authorization information, this is a finding.
V-274528
False
SRG-APP-000095-API-001765
Verify the API generates audit records of what type of events occurred.
1. Confirm audit logging is enabled for authentication and authorization events. This includes both successful and failed authentication attempts, as well as the authorization decisions (e.g., whether a user is granted or denied access).
2. Verify the logs capture relevant authentication and authorization details.
3. After performing tests, review the logs for entries related to authentication and authorization. Ensure that logs contain the appropriate level of detail (e.g., timestamps, user IDs, status codes).
If the API does not audit authentication and authorization information, this is a finding.
M
5703