Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Neil Smithline -- OWASP Top 10 #10: Logging

34 min23 mars 2018

Om avsnittet

A log file does little good if nobody can use it to detect or investigate an attack. Neil Smithline, a co-leader of the OWASP Top 10, explains why insufficient logging and monitoring became a new category in the 2017 edition. Chris and Robert explore the connection between application events, operational monitoring, and incident response, including what investigators lose when useful evidence is missing. Neil discusses security checklists, relevant OWASP guidance, and the difficult balance between recording enough context and exposing sensitive information. The conversation also considers automation, runtime instrumentation, and closer cooperation between development and response teams. Its central challenge is moving beyond a compliance checkbox toward logs that are protected, reviewed, and connected to meaningful action when something goes wrong.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Neil Smithline:
Neil Smithline on GitHub

Mentioned in this episode:
OWASP Top 10 project repository
OWASP Logging Cheat Sheet
OWASP ASVS
OWASP AppSensor

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Logging and monitoring in the OWASP Top 10
01:45 What insufficient logging and monitoring means
04:03 Generating useful events and reviewing them
05:58 Why incident response depends on logs
08:43 Assessing logging with a checklist
11:57 OWASP resources for better logging
12:57 Lessons from real incidents
15:47 Avoiding sensitive information in logs
18:15 Passwords, account identifiers, and data exposure
20:34 What better logging could look like
23:31 Could runtime instrumentation help?
27:14 Connecting developers and incident responders
31:13 Moving beyond compliance-only logging

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.