STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must refresh assertions in accordance with organization-defined identification and authentication policy.

DISA Rule

SV-274843r1143888_rule

Vulnerability Number

V-274843

Group Title

SRG-APP-000985

Rule Version

SRG-APP-000985-API-001675

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to refresh assertions in accordance with organization-defined identification and authentication policy.

Check Contents

Check if the API refreshes assertions in accordance with the organization-defined identification and authentication policy.

Review the API's handling of assertion expiration and renewal.

Ensure the API follows the organization's defined policies for assertion lifetime, including the duration before assertions need to be refreshed or reissued.

Check if the API requires reauthentication or uses a secure refresh mechanism, such as refresh tokens or secure revalidation processes, to generate new assertions when they expire.

Verify the process for refreshing assertions maintains security standards, including proper encryption, secure token storage, and validation of the refreshed assertions before they are issued.

Review the API's implementation to confirm it adheres to the organization's authentication policy for refreshing, ensuring that refreshed assertions include up-to-date identity information and relevant claims, and that they are properly scoped.

Test the API by requesting new assertions after expiration and examining whether they are refreshed securely and according to policy, ensuring compliance with the organization's standards for identity management and authentication.

If the API does not refresh assertions in accordance with organization-defined identification and authentication policy, this is a finding.

Vulnerability Number

V-274843

Documentable

False

Rule Version

SRG-APP-000985-API-001675

Severity Override Guidance

Check if the API refreshes assertions in accordance with the organization-defined identification and authentication policy.

Review the API's handling of assertion expiration and renewal.

Ensure the API follows the organization's defined policies for assertion lifetime, including the duration before assertions need to be refreshed or reissued.

Check if the API requires reauthentication or uses a secure refresh mechanism, such as refresh tokens or secure revalidation processes, to generate new assertions when they expire.

Verify the process for refreshing assertions maintains security standards, including proper encryption, secure token storage, and validation of the refreshed assertions before they are issued.

Review the API's implementation to confirm it adheres to the organization's authentication policy for refreshing, ensuring that refreshed assertions include up-to-date identity information and relevant claims, and that they are properly scoped.

Test the API by requesting new assertions after expiration and examining whether they are refreshed securely and according to policy, ensuring compliance with the organization's standards for identity management and authentication.

If the API does not refresh assertions in accordance with organization-defined identification and authentication policy, this is a finding.

Check Content Reference

M

Target Key

5703