STIGQter STIGQter: STIG Summary:

Application Programming Interface (API) Security Requirements Guide

Version: 1

Release: 1 Benchmark Date: 11 Sep 2025

CheckedNameTitle
☐SV-274497r1142303_ruleThe API must encrypt data in transit.
☐SV-274507r1143927_ruleThe API must be configured to use approved authorizations for access control.
☐SV-274517r1143512_ruleThe API must enable monitoring and alerts.
☐SV-274519r1143513_ruleThe API Gateway must generate audit records when successful/unsuccessful attempts to access privileges occur.
☐SV-274520r1143514_ruleThe API must generate audit records when successful/unsuccessful attempts to access privileges occur.
☐SV-274522r1143515_ruleThe API Gateway must generate audit records of what type of events occurred.
☐SV-274523r1143516_ruleThe API must monitor the usage of API keys to detect any anomalies.
☐SV-274524r1143517_ruleThe API must generate audit records of what type of events occurred.
☐SV-274525r1143929_ruleThe API must audit rate-limiting events.
☐SV-274526r1143552_ruleThe API Gateway must audit rate limiting events.
☐SV-274527r1143553_ruleThe API Gateway must audit authentication and authorization information.
☐SV-274528r1143554_ruleThe API must audit authentication and authorization information.
☐SV-274529r1143555_ruleThe API Gateway must audit exceptions and errors that occur during the processing.
☐SV-274530r1143557_ruleThe API must audit exceptions and errors that occur during the processing.
☐SV-274531r1143559_ruleThe API Gateway must audit execution time and performance metrics.
☐SV-274532r1143561_ruleThe API must audit execution time and performance metrics.
☐SV-274533r1143563_ruleThe API Gateway must audit request and response details (such as method, URL, headers, body, status, etc.).
☐SV-274534r1143565_ruleThe API must audit request and response details (such as method, URL, headers, body, status, etc.).
☐SV-274537r1143570_ruleAll defined API elements must be documented.
☐SV-274556r1143589_ruleAPI keys must be configured with usage restrictions.
☐SV-274557r1143590_ruleThe API must limit the exposure of endpoints.
☐SV-274559r1143592_ruleThe API must use an approved DOD enterprise identity, credential, and access management (ICAM) solution to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
☐SV-274600r1143633_ruleThe API must protect Session IDs via encryption.
☐SV-274603r1143636_ruleThe API keys must be securely generated using a FIPS-validated Random Number Generator (RNG).
☐SV-274606r1143639_ruleThe API implementation must use FIPS-validated encryption and hashing algorithms to protect the confidentiality and integrity of API keys.
☐SV-274607r1143640_ruleThe API must encrypt sensitive cached data.
☐SV-274612r1143931_ruleThe API must employ throttling.
☐SV-274613r1143646_ruleThe API must specify allowed origins when using Cross-Origin Resource Sharing (CORS).
☐SV-274615r1143648_ruleThe API must not disclose sensitive data in error messages.
☐SV-274643r1143676_ruleAccess to API privileged features and functions must be restricted.
☐SV-274672r1143705_ruleThe API must require periodic reauthentication.
☐SV-274677r1143710_ruleThe API must have a mechanism for cache invalidation when using cache policy data.
☐SV-274678r1143711_ruleWhen stateless authentication tokens are used, the API must configure them with appropriate security settings.
☐SV-274679r1143712_ruleThe API's internal authorization tokens must not be provided back to the user.
☐SV-274680r1143713_ruleAPI access tokens must be configured to expire.
☐SV-274681r1143714_ruleAPI refresh tokens must be configured to expire.
☐SV-274682r1143925_ruleThe API must enforce per-client rate limits.
☐SV-274697r1143731_ruleClients must be configured to route requests through a single API gateway that enforces the association and transmission of organization-defined security attributes with each request.
☐SV-274707r1143741_ruleThe API must use a gateway.
☐SV-274709r1143744_ruleThe amount of data returned by the API must be restricted.
☐SV-274710r1143745_ruleThe API must use TLS version 1.2 at a minimum.
☐SV-274712r1143748_ruleThe API must audience-restrict access tokens in accordance with organization-defined identification and authentication policy.
☐SV-274714r1143751_ruleThe API must use parameterized queries.
☐SV-274715r1143753_ruleThe API must provide input validation.
☐SV-274723r1143761_ruleThe API must authenticate remote commands.
☐SV-274767r1143805_ruleThe API must encode outputs.
☐SV-274768r1143806_ruleThe API must use a static type of system.
☐SV-274769r1143807_ruleThe API must use Web Application Firewall (WAF).
☐SV-274783r1143932_ruleThe API must use a FIPS-validated cryptographic module to provision digital signatures for tokens.
☐SV-274785r1143921_ruleAPI services identified within the system as unnecessary and/or nonsecure must be disabled.
☐SV-274830r1143869_ruleThe API must provide protected storage for API keys.
☐SV-274835r1143875_ruleAPI must use a circuit breaker pattern to handle failures and timeouts.
☐SV-274839r1143880_ruleCryptographic keys that protect access tokens must be protected.
☐SV-274840r1143882_ruleThe API must protect the private keys used to sign assertions and tokens.
☐SV-274841r1143884_ruleGenerating assertions must be restricted.
☐SV-274842r1143886_ruleThe API must issue assertions in accordance with organization-defined identification and authentication policy.
☐SV-274843r1143888_ruleThe API must refresh assertions in accordance with organization-defined identification and authentication policy.
☐SV-274844r1143890_ruleThe API must revoke assertions in accordance with organization-defined identification and authentication policy.
☐SV-274845r1143892_ruleThe API must time-restrict assertions in accordance with organization-defined identification and authentication policy.
☐SV-274846r1143894_ruleThe API must audience-restrict assertions in accordance with organization-defined identification and authentication policy.
☐SV-274847r1143896_ruleThe API must generate access tokens in accordance with organization-defined identification and authentication policy.
☐SV-274848r1143898_ruleThe API must issue access tokens in accordance with organization-defined identification and authentication policy.
☐SV-274849r1143900_ruleThe API must refresh access tokens in accordance with organization-defined identification and authentication policy.
☐SV-274850r1143901_ruleThe API must revoke access tokens in accordance with organization-defined identification and authentication policy.
☐SV-274851r1143903_ruleThe API must time-restrict access tokens in accordance with organization-defined identification and authentication policy.