Skip to main content
APPLICATION-SECURITY5 MIN READ

Logs Need a Security Question

Design application logs that support security detection and investigation without leaking sensitive data.

More logs do not create visibility. Better questions do. Start from the investigation Ask what you would need to know if the action were abused. For a sensitive export, you need actor, tenant, object type, approximate volume, decision, time, and correlation ID. For an authorization denial, you need subject, object, action, reason class, and request ID. For an admin setting change, you need before and after classes, not secret values. Avoid the two logging failures The first failure is under-logging: the system records page views but not security decisions. The second is over-logging: the system records tokens, passwords, full PII…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us