23 April 2012

Guide to Application Security Event Logging

Application logging, and in particular, application security logging may not sound the most exciting of subjects, but it really can be a very useful tool that helps during development and operation.

Photograph of the world's first practical electronic digital information processing machine - Colossus - at Bletchley Park, UK

If you remember, I have written about application security logging a number of times before. I have now consolidated all that information, and more, into a new document for the OWASP cheat sheet series about application logging that explains the benefits and details:

  • Design, implementation and testing
    • Event data sources
    • Where to record event data
    • Which events to log
    • Event attributes
    • Data to exclude
    • Customisable logging
    • Event collection
    • Testing
  • Deployment and operation
    • Release
    • Operation
    • Protection
    • Monitoring of events
    • Disposal of logs

The cheat sheet guide is a wiki page, so if you have any contributions, please add them. If you know any other good reference articles, I would like to hear about them.

This week I will be at Security B-Sides London, which my company is co-sponsoring. If you are there too on Wednesday, say hello.

Posted on: 23 April 2012 at 22:31 hrs

Comments Comments (2) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Do you think that there is a distinction between an audit log/trail and an application log? The audit trail being aimed more at assisting in more formal audit activities e.g. who logged on when etc. While an application log assists developers in debugging and general trouble-shooting?
1 Added by Alexis Posted on 24 April 2012 at 15:25 hrs
Yes there is. And I think you have spotted an area where the cheat sheet could be improved. It should talk about the logging purpose, and recommend separate logs for different purposes, especially since you would use an audit trail in a very different manner to an error and mis-use log.

Would you like to update the cheat sheet perhaps, or shall I draft something?
2 Added by Clerkendweller Posted on 24 April 2012 at 16:52 hrs
Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Guide to Application Security Event Logging
http://www.clerkendweller.com/2012/4/23/Guide-to-Application-Security-Event-Logging
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2012/4/23/Guide-to-Application-Security-Event-Logging
Requested by 50.16.108.167 on Thursday, 20 June 2013 at 03:51 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2012-2013 clerkendweller.com