EPISODE · Mar 23, 2018 · 33 MIN
Neil Smithline -- OWASP Top 10 #10: Logging
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
A log file does little good if nobody can use it to detect or investigate an attack. Neil Smithline, a co-leader of the OWASP Top 10, explains why insufficient logging and monitoring became a new category in the 2017 edition. Chris and Robert explore the connection between application events, operational monitoring, and incident response, including what investigators lose when useful evidence is missing. Neil discusses security checklists, relevant OWASP guidance, and the difficult balance between recording enough context and exposing sensitive information. The conversation also considers automation, runtime instrumentation, and closer cooperation between development and response teams. Its central challenge is moving beyond a compliance checkbox toward logs that are protected, reviewed, and connected to meaningful action when something goes wrong.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Neil Smithline:→ Neil Smithline on GitHubMentioned in this episode:→ OWASP Top 10 project repository→ OWASP Logging Cheat Sheet→ OWASP ASVS→ OWASP AppSensorFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Logging and monitoring in the OWASP Top 1001:45 What insufficient logging and monitoring means04:03 Generating useful events and reviewing them05:58 Why incident response depends on logs08:43 Assessing logging with a checklist11:57 OWASP resources for better logging12:57 Lessons from real incidents15:47 Avoiding sensitive information in logs18:15 Passwords, account identifiers, and data exposure20:34 What better logging could look like23:31 Could runtime instrumentation help?27:14 Connecting developers and incident responders31:13 Moving beyond compliance-only logging
Embed this episode
What this episode covers
A log file does little good if nobody can use it to detect or investigate an attack. Neil Smithline, a co-leader of the OWASP Top 10, explains why insufficient logging and monitoring became a new category in the 2017 edition. Chris and Robert explore the connection between application events, operational monitoring, and incident response, including what investigators lose when useful evidence is missing. Neil discusses security checklists, relevant OWASP guidance, and the difficult balance be...
Ready to play
Neil Smithline -- OWASP Top 10 #10: Logging
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.