SV-274710r1143745_rule
V-274710
SRG-APP-000439
SRG-APP-000439-API-001010
CAT I
10
Build or configure all of the API systems to require TLS (version 1.2 or higher) for all communication encryption in accordance with data protection requirements.
Verify the API uses TLS version 1.2 at a minimum.
Review the API documentation and interview the API administrator.
Identify API clients, servers and associated network connections including API networking ports.
Review API documents for instructions or guidance on configuring API encryption settings.
Verify the API is configured to enable encryption protections for data in accordance with the data protection requirements. If no data protection requirements exist, ensure all API data is encrypted.
If the API does not utilize TLS or another approved encryption mechanism to protect the confidentiality and integrity of transmitted information, this is a finding.
V-274710
False
SRG-APP-000439-API-001010
Verify the API uses TLS version 1.2 at a minimum.
Review the API documentation and interview the API administrator.
Identify API clients, servers and associated network connections including API networking ports.
Review API documents for instructions or guidance on configuring API encryption settings.
Verify the API is configured to enable encryption protections for data in accordance with the data protection requirements. If no data protection requirements exist, ensure all API data is encrypted.
If the API does not utilize TLS or another approved encryption mechanism to protect the confidentiality and integrity of transmitted information, this is a finding.
M
5703