STIGQter STIGQter: STIG Summary:

Application Programming Interface (API) Security Requirements Guide

Version: 1

Release: 1 Benchmark Date: 11 Sep 2025

CheckedNameTitle
SV-274497r1142303_ruleThe API must encrypt data in transit.
SV-274507r1143927_ruleThe API must be configured to use approved authorizations for access control.
SV-274517r1143512_ruleThe API must enable monitoring and alerts.
SV-274519r1143513_ruleThe API Gateway must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-274520r1143514_ruleThe API must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-274522r1143515_ruleThe API Gateway must generate audit records of what type of events occurred.
SV-274523r1143516_ruleThe API must monitor the usage of API keys to detect any anomalies.
SV-274524r1143517_ruleThe API must generate audit records of what type of events occurred.
SV-274525r1143929_ruleThe API must audit rate-limiting events.
SV-274526r1143552_ruleThe API Gateway must audit rate limiting events.
SV-274527r1143553_ruleThe API Gateway must audit authentication and authorization information.
SV-274528r1143554_ruleThe API must audit authentication and authorization information.
SV-274529r1143555_ruleThe API Gateway must audit exceptions and errors that occur during the processing.
SV-274530r1143557_ruleThe API must audit exceptions and errors that occur during the processing.
SV-274531r1143559_ruleThe API Gateway must audit execution time and performance metrics.
SV-274532r1143561_ruleThe API must audit execution time and performance metrics.
SV-274533r1143563_ruleThe API Gateway must audit request and response details (such as method, URL, headers, body, status, etc.).
SV-274534r1143565_ruleThe API must audit request and response details (such as method, URL, headers, body, status, etc.).
SV-274537r1143570_ruleAll defined API elements must be documented.
SV-274556r1143589_ruleAPI keys must be configured with usage restrictions.
SV-274557r1143590_ruleThe API must limit the exposure of endpoints.
SV-274559r1143592_ruleThe API must use an approved DOD enterprise identity, credential, and access management (ICAM) solution to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-274600r1143633_ruleThe API must protect Session IDs via encryption.
SV-274603r1143636_ruleThe API keys must be securely generated using a FIPS-validated Random Number Generator (RNG).
SV-274606r1143639_ruleThe API implementation must use FIPS-validated encryption and hashing algorithms to protect the confidentiality and integrity of API keys.
SV-274607r1143640_ruleThe API must encrypt sensitive cached data.
SV-274612r1143931_ruleThe API must employ throttling.
SV-274613r1143646_ruleThe API must specify allowed origins when using Cross-Origin Resource Sharing (CORS).
SV-274615r1143648_ruleThe API must not disclose sensitive data in error messages.
SV-274643r1143676_ruleAccess to API privileged features and functions must be restricted.
SV-274672r1143705_ruleThe API must require periodic reauthentication.
SV-274677r1143710_ruleThe API must have a mechanism for cache invalidation when using cache policy data.
SV-274678r1143711_ruleWhen stateless authentication tokens are used, the API must configure them with appropriate security settings.
SV-274679r1143712_ruleThe API's internal authorization tokens must not be provided back to the user.
SV-274680r1143713_ruleAPI access tokens must be configured to expire.
SV-274681r1143714_ruleAPI refresh tokens must be configured to expire.
SV-274682r1143925_ruleThe API must enforce per-client rate limits.
SV-274697r1143731_ruleClients must be configured to route requests through a single API gateway that enforces the association and transmission of organization-defined security attributes with each request.
SV-274707r1143741_ruleThe API must use a gateway.
SV-274709r1143744_ruleThe amount of data returned by the API must be restricted.
SV-274710r1143745_ruleThe API must use TLS version 1.2 at a minimum.
SV-274712r1143748_ruleThe API must audience-restrict access tokens in accordance with organization-defined identification and authentication policy.
SV-274714r1143751_ruleThe API must use parameterized queries.
SV-274715r1143753_ruleThe API must provide input validation.
SV-274723r1143761_ruleThe API must authenticate remote commands.
SV-274767r1143805_ruleThe API must encode outputs.
SV-274768r1143806_ruleThe API must use a static type of system.
SV-274769r1143807_ruleThe API must use Web Application Firewall (WAF).
SV-274783r1143932_ruleThe API must use a FIPS-validated cryptographic module to provision digital signatures for tokens.
SV-274785r1143921_ruleAPI services identified within the system as unnecessary and/or nonsecure must be disabled.
SV-274830r1143869_ruleThe API must provide protected storage for API keys.
SV-274835r1143875_ruleAPI must use a circuit breaker pattern to handle failures and timeouts.
SV-274839r1143880_ruleCryptographic keys that protect access tokens must be protected.
SV-274840r1143882_ruleThe API must protect the private keys used to sign assertions and tokens.
SV-274841r1143884_ruleGenerating assertions must be restricted.
SV-274842r1143886_ruleThe API must issue assertions in accordance with organization-defined identification and authentication policy.
SV-274843r1143888_ruleThe API must refresh assertions in accordance with organization-defined identification and authentication policy.
SV-274844r1143890_ruleThe API must revoke assertions in accordance with organization-defined identification and authentication policy.
SV-274845r1143892_ruleThe API must time-restrict assertions in accordance with organization-defined identification and authentication policy.
SV-274846r1143894_ruleThe API must audience-restrict assertions in accordance with organization-defined identification and authentication policy.
SV-274847r1143896_ruleThe API must generate access tokens in accordance with organization-defined identification and authentication policy.
SV-274848r1143898_ruleThe API must issue access tokens in accordance with organization-defined identification and authentication policy.
SV-274849r1143900_ruleThe API must refresh access tokens in accordance with organization-defined identification and authentication policy.
SV-274850r1143901_ruleThe API must revoke access tokens in accordance with organization-defined identification and authentication policy.
SV-274851r1143903_ruleThe API must time-restrict access tokens in accordance with organization-defined identification and authentication policy.