New Year's Resolution
What will be your new year's resolution? I would like to suggest a work-related one should be "implementing proper application logging" for web products.
Construction sites and manufacturing facilities routinely publish safety statistics such as "hours since last lost time incident", "number of man hours worked without a reportable accident" and other performance metrics. How about "days since last vulnerability exploited" or "days since last vulnerability reported"?
Without good application logging, you do not know the real performance of your system, whether there have been attacks, what suspicious activity has been occurring. You also will not have much information to examine to determine the cause of previous problems, generate meaningful security metrics, or build feedback mechanisms to improve security.
Put it near the top of the "to do" list for 2011. And have a good, safe & secure night!
Posted on: 31 December 2010 at 12:31 hrs

Comments are filtered automatically and should appear shortly after they been checked.