Verify that all logging components appropriately encode data to prevent log injection. (C9)
Level 1 required: False
Level 2 required: True
Level 3 required: True
CWE: 117
[DELETED, DUPLICATE OF 7.3.1]
Level 1 required: False
Level 2 required: False
Level 3 required: False
Verify that security logs are protected from unauthorized access and modification. (C9)
Level 1 required: False
Level 2 required: True
Level 3 required: True
CWE: 200
Verify that time sources are synchronized to the correct time and time zone. Strongly consider logging only in UTC if systems are global to assist with post-incident forensic analysis. (C9)
Level 1 required: False
Level 2 required: True
Level 3 required: True
Credit via OWASP ASVS. For more information visit The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v3.0 license.
Loading comments 0%