STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

API keys must be configured with usage restrictions.

DISA Rule

SV-274556r1143589_rule

Vulnerability Number

V-274556

Group Title

SRG-APP-000141

Rule Version

SRG-APP-000141-API-000240

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Update the API key configurations to include appropriate usage restrictions (limiting access by IP address, allowed endpoints, request methods, and environment scope) in accordance with organizational defined standards.

Check Contents

Review the API key configurations. If any API keys lack defined usage restrictions (IP address filtering, endpoint access limitations, and environment scoping) this is a finding.

Vulnerability Number

V-274556

Documentable

False

Rule Version

SRG-APP-000141-API-000240

Severity Override Guidance

Review the API key configurations. If any API keys lack defined usage restrictions (IP address filtering, endpoint access limitations, and environment scoping) this is a finding.

Check Content Reference

M

Target Key

5703