Log Protection
V16.4.1
Verify that all logging components appropriately encode data to prevent log injection.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 120, 152, 153, 242, 248, 267, 268, 28, 88, 93
V16.4.2
Verify that logs are protected from unauthorized access and cannot be modified.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 116, 150, 169, 215, 268, 54
V16.4.3
Verify that logs are securely transmitted to a logically separate system for analysis, detection, alerting, and escalation. The aim is to ensure that if the application is breached, the logs are not compromised.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 151, 21, 268, 49, 50, 600
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.