OWASP ASVS
V7 Error Handling and Logging

OWASP ASVS OWASPASVS-7: Error Handling and Logging (V7)

Per OWASP ASVS V7: implement secure error handling + logging. Requirements include (a) handle errors without leaking sensitive information (stack traces + internal paths + database errors) to users + (b) log security-relevant events including authentication + authorisation + access control + administrative actions + cryptographic operations + (c) protect log integrity (write-once or cryptographic hashing) + confidentiality + availability + (d) include sufficient context for investigation (timestamp + user + source + action + result) + (e) maintain retention aligned to regulatory + investigative + governance requirements + (f) integrate with SIEM + monitoring + alerting + (g) protect against log injection + log forging attacks.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.