H. of Repudiation I
Our audit log contains personal data, and we do not record who looks at our audit logs.
Threat |
|
You are not reviewing what should be logged and are logging personal data when you should not. |
|
CAPEC |
N/A |
ASVS |
7.1.1 - Ensure that secrets and payment card details including CVV numbers are not being logged. 7.1.2 - Ensure PII and other sensitive data being logged complies with regulations. 7.1.3 - Ensure security events are being logged. 8.3.5 - Ensure you have an audit trail for all sensitive data access. |
CWE |
CWE-215 - Insertion of Sensitive Information into Debugging Code |
Mitigations |
|
... |