STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must use Web Application Firewall (WAF).

DISA Rule

SV-274769r1143807_rule

Vulnerability Number

V-274769

Group Title

SRG-APP-000516

Rule Version

SRG-APP-000516-API-001305

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to use a WAF or API Gateway to manage traffic.

Check Contents

Verify the API is configured to use a WAF or API Gateway to manage traffic.

If the API is not configured to use a WAF or API Gateway in accordance with organization-defined security policies, this is a finding.

Vulnerability Number

V-274769

Documentable

False

Rule Version

SRG-APP-000516-API-001305

Severity Override Guidance

Verify the API is configured to use a WAF or API Gateway to manage traffic.

If the API is not configured to use a WAF or API Gateway in accordance with organization-defined security policies, this is a finding.

Check Content Reference

M

Target Key

5703