STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must audit execution time and performance metrics.

DISA Rule

SV-274532r1143561_rule

Vulnerability Number

V-274532

Group Title

SRG-APP-000095

Rule Version

SRG-APP-000095-API-001785

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to track and log performance data, including response times and throughput.

Check Contents

Verify the API audits execution time and performance metrics.

1. Inspect the API's logs to ensure they capture execution times, request latency, and other performance metrics.

2. Simulate various requests and verify execution time and performance metrics are logged correctly.

3. Verify the API is configured to track and log performance data, including response times and throughput.

4. Review the API's documentation to ensure execution time and performance auditing is enabled.

If the API is not auditing execution time and performance metrics, this is a finding.

Vulnerability Number

V-274532

Documentable

False

Rule Version

SRG-APP-000095-API-001785

Severity Override Guidance

Verify the API audits execution time and performance metrics.

1. Inspect the API's logs to ensure they capture execution times, request latency, and other performance metrics.

2. Simulate various requests and verify execution time and performance metrics are logged correctly.

3. Verify the API is configured to track and log performance data, including response times and throughput.

4. Review the API's documentation to ensure execution time and performance auditing is enabled.

If the API is not auditing execution time and performance metrics, this is a finding.

Check Content Reference

M

Target Key

5703