STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must use an approved DOD enterprise identity, credential, and access management (ICAM) solution to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).

DISA Rule

SV-274559r1143592_rule

Vulnerability Number

V-274559

Group Title

SRG-APP-000148

Rule Version

SRG-APP-000148-API-000255

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the API to use an approved DOD enterprise ICAM solution.

Check Contents

Review the API documentation and interview the API administrator to determine access methods to the API.

Attempt to access the API and confirm that an approved DOD enterprise ICAM solution is required for an external client to establish initial access to the API. Authentication of subsequent calls to the API may be accomplished using a time-limited credential such as an API key or JWT.

If the API does not use an approved DOD enterprise ICAM solution for external clients to establish initial access, this is a finding.

Vulnerability Number

V-274559

Documentable

False

Rule Version

SRG-APP-000148-API-000255

Severity Override Guidance

Review the API documentation and interview the API administrator to determine access methods to the API.

Attempt to access the API and confirm that an approved DOD enterprise ICAM solution is required for an external client to establish initial access to the API. Authentication of subsequent calls to the API may be accomplished using a time-limited credential such as an API key or JWT.

If the API does not use an approved DOD enterprise ICAM solution for external clients to establish initial access, this is a finding.

Check Content Reference

M

Target Key

5703