Queen of Repudiation I
An attacker can say, “I didn’t do that,” and you’d have no way to prove them wrong.
Threat |
|
You are not putting usernames or some other identifier into your audit trail entries, so you can’t trace an action that was performed back to the individual who performed it. |
|
CAPEC |
N/A |
ASVS |
7.1.3 - Ensure security events are being logged. |
CWE |
CWE-778 - Insufficient Logging CWE-223 - Omission of Security-Relevant Information |
Mitigations |
|
|