SRG-APP-000400 Controls

STIG IDVersionTitleProduct
SRG-APP-000400-API-000845V1R1The API must have a mechanism for cache invalidation when using cache policy data.
SRG-APP-000400-API-000850V1R1When stateless authentication tokens are used, the API must configure them with appropriate security settings.
SRG-APP-000400-API-000855V1R1The API's internal authorization tokens must not be provided back to the user.
SRG-APP-000400-API-000860V1R1API access tokens must be configured to expire.
SRG-APP-000400-API-000865V1R1API refresh tokens must be configured to expire.
SRG-APP-000247-API-000870V1R1The API must enforce per-client rate limits.
SRG-APP-000400-CTR-000960V2R3The container platform must prohibit the use of cached authenticators after an organization-defined time period.
SRG-APP-000400-MFP-000241V3R3The Mainframe Product must prohibit the use of cached authenticators after one hour.