STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

API services identified within the system as unnecessary and/or nonsecure must be disabled.

DISA Rule

SV-274785r1143921_rule

Vulnerability Number

V-274785

Group Title

SRG-APP-000645

Rule Version

SRG-APP-000645-API-001385

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to use necessary and secure services and ports approved by the PPSM CAL.

Check Contents

Verify API services identified within the system as unnecessary and/or nonsecure are disabled.

Review the API documentation and configuration.

Interview the API administrator.

Identify the services, network ports, and protocols used by the API.

Using a combination of relevant OS commands and API configuration utilities, identify the services and TCP/IP port numbers the API is configured to use and is using.

Review the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) at https://cyber.mil/ppsm/cal/.

Verify the ports used by the API are approved by the PPSM CAL.

If the ports and services are not approved by the PPSM CAL, this is a finding.

Vulnerability Number

V-274785

Documentable

False

Rule Version

SRG-APP-000645-API-001385

Severity Override Guidance

Verify API services identified within the system as unnecessary and/or nonsecure are disabled.

Review the API documentation and configuration.

Interview the API administrator.

Identify the services, network ports, and protocols used by the API.

Using a combination of relevant OS commands and API configuration utilities, identify the services and TCP/IP port numbers the API is configured to use and is using.

Review the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) at https://cyber.mil/ppsm/cal/.

Verify the ports used by the API are approved by the PPSM CAL.

If the ports and services are not approved by the PPSM CAL, this is a finding.

Check Content Reference

M

Target Key

5703