Skip to main content
CUI

Documentation - V-274530

V-274530

Application Programming Interface (API) Security Requirements Guide

CAT II

Title

The API must audit exceptions and errors that occur during the processing.

Description

<VulnDiscussion>Without establishing what type of event occurred, it would be difficult to establish, correlate, and investigate the events relating to an incident, or identify those responsible for one. Audit record content that may be necessary to satisfy the requirement of this policy includes, for example, time stamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoke...

Fix Text (Documentation Requirement)

Build or configure the API to log exceptions and errors with sufficient detail for troubleshooting and analysis.

Documentation Status

Cancel
CUI