SV-274537r1143570_rule
V-274537
SRG-APP-000098
SRG-APP-000098-API-000145
CAT II
10
Update the documentation to include all defined API elements and their security-relevant configurations. Ensure each element is properly logged and monitored in accordance with the organization's approved security baselines.
To identify APIs in use:
Analyze application code for API calls, URLs, and authentication keys in frontend and backend components.
Use network monitoring tools to capture API traffic in real time.
Check browser DevTools (Network tab) for active API requests in web applications.
Review server and API gateway logs (e.g., AWS CloudWatch, Nginx logs) to track API calls and usage patterns.
Inspect configuration files, environment variables, and documentation for references to external or internal APIs.
If any defined API elements or their security-relevant configurations are not documented and enforced in accordance with the organization's approved security baselines, this is a finding.
V-274537
False
SRG-APP-000098-API-000145
To identify APIs in use:
Analyze application code for API calls, URLs, and authentication keys in frontend and backend components.
Use network monitoring tools to capture API traffic in real time.
Check browser DevTools (Network tab) for active API requests in web applications.
Review server and API gateway logs (e.g., AWS CloudWatch, Nginx logs) to track API calls and usage patterns.
Inspect configuration files, environment variables, and documentation for references to external or internal APIs.
If any defined API elements or their security-relevant configurations are not documented and enforced in accordance with the organization's approved security baselines, this is a finding.
M
5703