STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must issue assertions in accordance with organization-defined identification and authentication policy.

DISA Rule

SV-274842r1143886_rule

Vulnerability Number

V-274842

Group Title

SRG-APP-000980

Rule Version

SRG-APP-000980-API-001670

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to issue assertions in accordance with organization-defined identification and authentication policy.

Check Contents

Reviewing the API's authentication and authorization mechanisms. Verify the assertions are issued using the correct identity source's identity provider (IdP).

Verify the API adheres to the defined authentication standards to ensure that only authenticated and authorized entities can issue assertions.

Check the assertions include necessary identity information (e.g., user ID, roles, and claims) and are signed or encrypted.

Validate the issued process is compliant with any guidelines regarding assertion lifetime, scope, and audience.

Check that the API enforces rules for assertion expiration, audience restrictions, and security measures like encryption or digital signatures, ensuring assertions cannot be tampered with or misused.

Consult the organization's identity management documentation and compare it to the API's implementation to ensure full alignment with the defined policies.

If the API is not issuing assertions in accordance with organization-defined identification and authentication policy, this is a finding.

Vulnerability Number

V-274842

Documentable

False

Rule Version

SRG-APP-000980-API-001670

Severity Override Guidance

Reviewing the API's authentication and authorization mechanisms. Verify the assertions are issued using the correct identity source's identity provider (IdP).

Verify the API adheres to the defined authentication standards to ensure that only authenticated and authorized entities can issue assertions.

Check the assertions include necessary identity information (e.g., user ID, roles, and claims) and are signed or encrypted.

Validate the issued process is compliant with any guidelines regarding assertion lifetime, scope, and audience.

Check that the API enforces rules for assertion expiration, audience restrictions, and security measures like encryption or digital signatures, ensuring assertions cannot be tampered with or misused.

Consult the organization's identity management documentation and compare it to the API's implementation to ensure full alignment with the defined policies.

If the API is not issuing assertions in accordance with organization-defined identification and authentication policy, this is a finding.

Check Content Reference

M

Target Key

5703