| Checked | Name | Title |
|---|
| ☐ | SV-274497r1142303_rule | The API must encrypt data in transit. |
| ☐ | SV-274507r1143927_rule | The API must be configured to use approved authorizations for access control. |
| ☐ | SV-274517r1143512_rule | The API must enable monitoring and alerts. |
| ☐ | SV-274519r1143513_rule | The API Gateway must generate audit records when successful/unsuccessful attempts to access privileges occur. |
| ☐ | SV-274520r1143514_rule | The API must generate audit records when successful/unsuccessful attempts to access privileges occur. |
| ☐ | SV-274522r1143515_rule | The API Gateway must generate audit records of what type of events occurred. |
| ☐ | SV-274523r1143516_rule | The API must monitor the usage of API keys to detect any anomalies. |
| ☐ | SV-274524r1143517_rule | The API must generate audit records of what type of events occurred. |
| ☐ | SV-274525r1143929_rule | The API must audit rate-limiting events. |
| ☐ | SV-274526r1143552_rule | The API Gateway must audit rate limiting events. |
| ☐ | SV-274527r1143553_rule | The API Gateway must audit authentication and authorization information. |
| ☐ | SV-274528r1143554_rule | The API must audit authentication and authorization information. |
| ☐ | SV-274529r1143555_rule | The API Gateway must audit exceptions and errors that occur during the processing. |
| ☐ | SV-274530r1143557_rule | The API must audit exceptions and errors that occur during the processing. |
| ☐ | SV-274531r1143559_rule | The API Gateway must audit execution time and performance metrics. |
| ☐ | SV-274532r1143561_rule | The API must audit execution time and performance metrics. |
| ☐ | SV-274533r1143563_rule | The API Gateway must audit request and response details (such as method, URL, headers, body, status, etc.). |
| ☐ | SV-274534r1143565_rule | The API must audit request and response details (such as method, URL, headers, body, status, etc.). |
| ☐ | SV-274537r1143570_rule | All defined API elements must be documented. |
| ☐ | SV-274556r1143589_rule | API keys must be configured with usage restrictions. |
| ☐ | SV-274557r1143590_rule | The API must limit the exposure of endpoints. |
| ☐ | SV-274559r1143592_rule | The API must use an approved DOD enterprise identity, credential, and access management (ICAM) solution to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). |
| ☐ | SV-274600r1143633_rule | The API must protect Session IDs via encryption. |
| ☐ | SV-274603r1143636_rule | The API keys must be securely generated using a FIPS-validated Random Number Generator (RNG). |
| ☐ | SV-274606r1143639_rule | The API implementation must use FIPS-validated encryption and hashing algorithms to protect the confidentiality and integrity of API keys. |
| ☐ | SV-274607r1143640_rule | The API must encrypt sensitive cached data. |
| ☐ | SV-274612r1143931_rule | The API must employ throttling. |
| ☐ | SV-274613r1143646_rule | The API must specify allowed origins when using Cross-Origin Resource Sharing (CORS). |
| ☐ | SV-274615r1143648_rule | The API must not disclose sensitive data in error messages. |
| ☐ | SV-274643r1143676_rule | Access to API privileged features and functions must be restricted. |
| ☐ | SV-274672r1143705_rule | The API must require periodic reauthentication. |
| ☐ | SV-274677r1143710_rule | The API must have a mechanism for cache invalidation when using cache policy data. |
| ☐ | SV-274678r1143711_rule | When stateless authentication tokens are used, the API must configure them with appropriate security settings. |
| ☐ | SV-274679r1143712_rule | The API's internal authorization tokens must not be provided back to the user. |
| ☐ | SV-274680r1143713_rule | API access tokens must be configured to expire. |
| ☐ | SV-274681r1143714_rule | API refresh tokens must be configured to expire. |
| ☐ | SV-274682r1143925_rule | The API must enforce per-client rate limits. |
| ☐ | SV-274697r1143731_rule | Clients must be configured to route requests through a single API gateway that enforces the association and transmission of organization-defined security attributes with each request. |
| ☐ | SV-274707r1143741_rule | The API must use a gateway. |
| ☐ | SV-274709r1143744_rule | The amount of data returned by the API must be restricted. |
| ☐ | SV-274710r1143745_rule | The API must use TLS version 1.2 at a minimum. |
| ☐ | SV-274712r1143748_rule | The API must audience-restrict access tokens in accordance with organization-defined identification and authentication policy. |
| ☐ | SV-274714r1143751_rule | The API must use parameterized queries. |
| ☐ | SV-274715r1143753_rule | The API must provide input validation. |
| ☐ | SV-274723r1143761_rule | The API must authenticate remote commands. |
| ☐ | SV-274767r1143805_rule | The API must encode outputs. |
| ☐ | SV-274768r1143806_rule | The API must use a static type of system. |
| ☐ | SV-274769r1143807_rule | The API must use Web Application Firewall (WAF). |
| ☐ | SV-274783r1143932_rule | The API must use a FIPS-validated cryptographic module to provision digital signatures for tokens. |
| ☐ | SV-274785r1143921_rule | API services identified within the system as unnecessary and/or nonsecure must be disabled. |
| ☐ | SV-274830r1143869_rule | The API must provide protected storage for API keys. |
| ☐ | SV-274835r1143875_rule | API must use a circuit breaker pattern to handle failures and timeouts. |
| ☐ | SV-274839r1143880_rule | Cryptographic keys that protect access tokens must be protected. |
| ☐ | SV-274840r1143882_rule | The API must protect the private keys used to sign assertions and tokens. |
| ☐ | SV-274841r1143884_rule | Generating assertions must be restricted. |
| ☐ | SV-274842r1143886_rule | The API must issue assertions in accordance with organization-defined identification and authentication policy. |
| ☐ | SV-274843r1143888_rule | The API must refresh assertions in accordance with organization-defined identification and authentication policy. |
| ☐ | SV-274844r1143890_rule | The API must revoke assertions in accordance with organization-defined identification and authentication policy. |
| ☐ | SV-274845r1143892_rule | The API must time-restrict assertions in accordance with organization-defined identification and authentication policy. |
| ☐ | SV-274846r1143894_rule | The API must audience-restrict assertions in accordance with organization-defined identification and authentication policy. |
| ☐ | SV-274847r1143896_rule | The API must generate access tokens in accordance with organization-defined identification and authentication policy. |
| ☐ | SV-274848r1143898_rule | The API must issue access tokens in accordance with organization-defined identification and authentication policy. |
| ☐ | SV-274849r1143900_rule | The API must refresh access tokens in accordance with organization-defined identification and authentication policy. |
| ☐ | SV-274850r1143901_rule | The API must revoke access tokens in accordance with organization-defined identification and authentication policy. |
| ☐ | SV-274851r1143903_rule | The API must time-restrict access tokens in accordance with organization-defined identification and authentication policy. |