E of Tampering I
Data in the database can be fixed by the admins, and nobody will ever know:
Threat |
|
Administrators have change access to the database for CRUD operations but there is no audit trail or approval process, so they can make changes without detection. |
|
CAPEC |
N/A |
ASVS |
7.1.3: Ensure security events are being logged 7.1.4: Ensure log entries contain all the necessary information for an investigation |
CWE |
CWE-778: Insufficient Logging |
Mitigations |
|
|