STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API implementation must use FIPS-validated encryption and hashing algorithms to protect the confidentiality and integrity of API keys.

DISA Rule

SV-274606r1143639_rule

Vulnerability Number

V-274606

Group Title

SRG-APP-000231

Rule Version

SRG-APP-000231-API-000490

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Identify data elements that require protection. Document the data types and specify protection requirements and methods used.

Check Contents

Verify that the API implementation uses FIPS-validated encryption and hashing algorithms to protect API keys. If non-FIPS-validated algorithms are used, or if encryption/hashing is absent, this is a finding.

Vulnerability Number

V-274606

Documentable

False

Rule Version

SRG-APP-000231-API-000490

Severity Override Guidance

Verify that the API implementation uses FIPS-validated encryption and hashing algorithms to protect API keys. If non-FIPS-validated algorithms are used, or if encryption/hashing is absent, this is a finding.

Check Content Reference

M

Target Key

5703