Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update A10_2017-Insufficient_Logging%26Monitoring.md #30

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions 2017/A10_2017-Insufficient_Logging%26Monitoring.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ In 2016, identifying a breach took an [average of 191 days](https://www-01.ibm.c

{%- include t10_subsection_begin.html -%}
{%- include t10_subsection.html token="isTheApplicationVulnerable" pos="firstLeft" -%}
Insufficient logging, detection, monitoring and active response occurs any time:<br>
Insufficient logging, detection, monitoring and active response never occurs:<br>
* Auditable events, such as logins, failed logins, and high-value transactions are not logged.<br>
* Warnings and errors generate no, inadequate, or unclear log messages.<br>
* Logs of applications and APIs are not monitored for suspicious activity.<br>
Expand Down Expand Up @@ -73,4 +73,4 @@ There are commercial and open source application protection frameworks such as [
**External**<br>
* [CWE-223: Omission of Security-relevant Information](https://cwe.mitre.org/data/definitions/223.html)<br>
* [CWE-778: Insufficient Logging](https://cwe.mitre.org/data/definitions/778.html)
{% include t10_subsection_end.html %}
{% include t10_subsection_end.html %}