SV-274707r1143741_rule
V-274707
SRG-APP-000435
SRG-APP-000435-API-000995
CAT II
10
Build or configure the API to use a gateway.
Note: The authorizing official (AO) may conduct a risk assessment if not using an API Gateway.
The API must be routed through a gateway that enforces protections against denial-of-service (DoS) attacks such as rate limiting, request throttling, and anomaly detection in accordance with organization-defined thresholds.
If the API does not use a gateway, this is a finding.
V-274707
False
SRG-APP-000435-API-000995
Note: The authorizing official (AO) may conduct a risk assessment if not using an API Gateway.
The API must be routed through a gateway that enforces protections against denial-of-service (DoS) attacks such as rate limiting, request throttling, and anomaly detection in accordance with organization-defined thresholds.
If the API does not use a gateway, this is a finding.
M
5703