Rule ID
SV-274769r1143807_rule
Version
V1R1
CCIs
CCI-000366
The API must be protected by a Web Application Firewall (WAF) or an API Gateway that monitors and filters incoming and outgoing traffic to prevent injection attacks, ensuring malicious inputs are detected and blocked.
Verify the API is configured to use a WAF or API Gateway to manage traffic. If the API is not configured to use a WAF or API Gateway in accordance with organization-defined security policies, this is a finding.
Build or configure the API to use a WAF or API Gateway to manage traffic.