STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

Generating assertions must be restricted.

DISA Rule

SV-274841r1143884_rule

Vulnerability Number

V-274841

Group Title

SRG-APP-000975

Rule Version

SRG-APP-000975-API-001665

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to generate assertions in accordance with organization-defined identification and authentication policy.

Check Contents

Review the API's authentication and authorization mechanisms. Ensure that the assertions are generated using the correct identity source's identity provider (IdP).

Verify the API adheres to the defined authentication standards to ensure only authenticated and authorized entities can generate assertions.

Check the assertions include necessary identity information (e.g., user ID, roles, and claims) and are signed or encrypted.

Verify the generation process is compliant with any guidelines regarding assertion lifetime, scope, and audience.

Review system logs to confirm the API is correctly implementing the authentication policies and generating assertions only after successful identity verification.

Consult the organization's identity management documentation and compare it to the API's implementation to ensure full alignment with the defined policies.

If the API is not generating assertions in accordance with organization-defined identification and authentication policy, this is a finding.

Vulnerability Number

V-274841

Documentable

False

Rule Version

SRG-APP-000975-API-001665

Severity Override Guidance

Review the API's authentication and authorization mechanisms. Ensure that the assertions are generated using the correct identity source's identity provider (IdP).

Verify the API adheres to the defined authentication standards to ensure only authenticated and authorized entities can generate assertions.

Check the assertions include necessary identity information (e.g., user ID, roles, and claims) and are signed or encrypted.

Verify the generation process is compliant with any guidelines regarding assertion lifetime, scope, and audience.

Review system logs to confirm the API is correctly implementing the authentication policies and generating assertions only after successful identity verification.

Consult the organization's identity management documentation and compare it to the API's implementation to ensure full alignment with the defined policies.

If the API is not generating assertions in accordance with organization-defined identification and authentication policy, this is a finding.

Check Content Reference

M

Target Key

5703