Checks whether an API in API Gateway is set to private.

Scenarios

When business production requirements are met, you can set APIs in API Gateway to private to reduce security risks.

Risk level

Default risk level: high.

You can change the risk level as required when you apply this rule.

Compliance evaluation logic

  • If the API in API Gateway is set to private, the evaluation result is compliant.
  • If the API in API Gateway is set to public, the evaluation result is non-compliant.

Rule details

Item Description
Rule name api-gateway-api-visibility-private
Rule ID api-gateway-api-visibility-private
Tag ApiGateway and API
Automatic remediation Not supported
Trigger type Configuration change
Supported resource type API resource
Input parameter None