STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must have a mechanism for cache invalidation when using cache policy data.

DISA Rule

SV-274677r1143710_rule

Vulnerability Number

V-274677

Group Title

SRG-APP-000400

Rule Version

SRG-APP-000400-API-000845

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to expire the cache policy data.

Check Contents

Verify the API has a mechanism for cache invalidation when using cache policy data.

It may be appropriate to allow microservices to cache policy data; however, this cache must only be relied upon when an access server is unavailable. The cached data must expire after a duration defined by the organization and appropriate for the specific environment/infrastructure.

If the API is not configured to expire cache policy data, this is a finding.

Vulnerability Number

V-274677

Documentable

False

Rule Version

SRG-APP-000400-API-000845

Severity Override Guidance

Verify the API has a mechanism for cache invalidation when using cache policy data.

It may be appropriate to allow microservices to cache policy data; however, this cache must only be relied upon when an access server is unavailable. The cached data must expire after a duration defined by the organization and appropriate for the specific environment/infrastructure.

If the API is not configured to expire cache policy data, this is a finding.

Check Content Reference

M

Target Key

5703