STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must use a gateway.

DISA Rule

SV-274707r1143741_rule

Vulnerability Number

V-274707

Group Title

SRG-APP-000435

Rule Version

SRG-APP-000435-API-000995

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to use a gateway.

Check Contents

Note: The authorizing official (AO) may conduct a risk assessment if not using an API Gateway.

The API must be routed through a gateway that enforces protections against denial-of-service (DoS) attacks such as rate limiting, request throttling, and anomaly detection in accordance with organization-defined thresholds.

If the API does not use a gateway, this is a finding.

Vulnerability Number

V-274707

Documentable

False

Rule Version

SRG-APP-000435-API-000995

Severity Override Guidance

Note: The authorizing official (AO) may conduct a risk assessment if not using an API Gateway.

The API must be routed through a gateway that enforces protections against denial-of-service (DoS) attacks such as rate limiting, request throttling, and anomaly detection in accordance with organization-defined thresholds.

If the API does not use a gateway, this is a finding.

Check Content Reference

M

Target Key

5703