Skip to content

Commit

Permalink
Make it clear that external sources will be needed
Browse files Browse the repository at this point in the history
  • Loading branch information
tghosth authored May 2, 2024
1 parent bae8399 commit dc7233d
Showing 1 changed file with 3 additions and 6 deletions.
9 changes: 3 additions & 6 deletions 5.0/en/0x15-V7-Error-Logging.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,14 +16,11 @@ It is also important to ensure that the application fails securely and that erro

## V7.1 General Logging

<!--
Logging sensitive information is dangerous - the logs become classified themselves, which means they need to be encrypted, become subject to retention policies, and must be disclosed in security audits. Ensure only necessary information is kept in logs, and certainly no payment, credentials (including session tokens), sensitive or personally identifiable information.

V7.1 covers OWASP Top 10 2017:A10. As 2017:A10 and this section are not penetration testable, it's important for:
Logging sensitive information is dangerous - the logs become classified themselves, which means they may need to be encrypted, become subject to retention policies, and must be disclosed in security audits. Ensure only necessary information is kept in logs, and certainly no payment, credentials (including session tokens), sensitive or personally identifiable information.

For there specific information which should be included in a log entry, refer to external detailed guidance such as the OWASP Logging Cheat Sheet.

* Developers to ensure full compliance with this section, as if all items were marked as L1.
* Penetration testers to validate full compliance of all items in V7.1 via interview, screenshots, or assertion.
-->

| # | Description | L1 | L2 | L3 | CWE |
| :---: | :--- | :---: | :---: | :---: | :---: |
Expand Down

0 comments on commit dc7233d

Please sign in to comment.