SV-274529r1143555_rule
V-274529
SRG-APP-000095
SRG-APP-000095-API-001770
CAT II
10
Build or configure the API Gateway to log errors and exceptions, including the level of detail, such as timestamps, error type, and affected resources.
If an API Gateway is not in use, this is Not Applicable.
Verify the API Gateway audits exceptions and errors that occur during the processing.
1. Inspect the API Gateway logs to ensure they capture exception and error events, including error codes, messages, and stack traces.
2. Simulate errors (e.g., invalid requests or server failures) and verify these are logged with relevant details like timestamps and error types.
3. Verify the API Gateway is configured to log exceptions and errors with sufficient detail for troubleshooting and analysis.
4. Review the API Gateway documentation support to ensure proper auditing of exceptions and errors is enabled.
If the API Gateway does not audit exceptions and errors, this is a finding.
V-274529
False
SRG-APP-000095-API-001770
If an API Gateway is not in use, this is Not Applicable.
Verify the API Gateway audits exceptions and errors that occur during the processing.
1. Inspect the API Gateway logs to ensure they capture exception and error events, including error codes, messages, and stack traces.
2. Simulate errors (e.g., invalid requests or server failures) and verify these are logged with relevant details like timestamps and error types.
3. Verify the API Gateway is configured to log exceptions and errors with sufficient detail for troubleshooting and analysis.
4. Review the API Gateway documentation support to ensure proper auditing of exceptions and errors is enabled.
If the API Gateway does not audit exceptions and errors, this is a finding.
M
5703