Medium APIGateway Regional

API Gateway routes should specify an authorization type

NIST

Description

This control checks if Amazon API Gateway routes have an authorization type specified.


Remediation

To set an authorization type for HTTP APIs, refer to the API Gateway Developer Guide.

Steps

  1. Navigate to the API Gateway console.
  2. Select the API and go to the Routes section.
  3. Specify an authorization type for each route.

Compliance

NIST