An API Gateway API is compliant if it is set to private.
Scenarios
Private APIs reduce security risks for your business.
Risk level
Default risk level: High.
You can change the risk level.
Detection logic
-
Compliant: The API is set to private.
-
Non-compliant: The API is set to public.
Rule details
|
Parameter |
Description |
|
Rule name |
Set APIs in API Gateway to private |
|
Rule identifier |
api-gateway-api-visibility-private |
|
Tags |
ApiGateway, API |
|
Automatic correction |
Not supported |
|
Rule trigger |
Configuration change |
|
Supported resource types |
API resources |
|
Rule input parameters |
None |