31 December 2010

New Year's Resolution

What will be your new year's resolution? I would like to suggest a work-related one should be "implementing proper application logging" for web products.

Photograph of a construction site's safety performance noticeboard showing the number of man hours worked without a reportable accident, the date the notice was updated, and the date of the last reportable accident (photograph taken at Farringdon Station, London during preparatory works for the Thameslink project)

Construction sites and manufacturing facilities routinely publish safety statistics such as "hours since last lost time incident", "number of man hours worked without a reportable accident" and other performance metrics. How about "days since last vulnerability exploited" or "days since last vulnerability reported"?

Without good application logging, you do not know the real performance of your system, whether there have been attacks, what suspicious activity has been occurring. You also will not have much information to examine to determine the cause of previous problems, generate meaningful security metrics, or build feedback mechanisms to improve security.

Put it near the top of the "to do" list for 2011. And have a good, safe & secure night!

Posted on: 31 December 2010 at 12:31 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
New Year's Resolution
http://www.clerkendweller.com/2010/12/31/New-Years-Resolution
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2010/12/31/New-Years-Resolution
Requested by 38.107.179.224 on Thursday, 17 May 2012 at 22:16 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2010-2012 clerkendweller.com