OWASP ASVS
V7 Error Handling and Logging

OWASP ASVS OWASPASVS-7: Error Handling and Logging (V7)

Per OWASP ASVS V7: implement secure error handling + logging. Requirements include (a) handle errors without leaking sensitive information (stack traces + internal paths + database errors) to users + (b) log security-relevant events including authentication + authorisation + access control + administrative actions + cryptographic operations + (c) protect log integrity (write-once or cryptographic hashing) + confidentiality + availability + (d) include sufficient context for investigation (timestamp + user + source + action + result) + (e) maintain retention aligned to regulatory + investigative + governance requirements + (f) integrate with SIEM + monitoring + alerting + (g) protect against log injection + log forging attacks.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 44 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM
  • IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection

MARS-E · 2 controls

FDA 21 CFR Part 11 · 1 control

  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))

FISMA · 1 control

  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP Rev 5 · 1 control

  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests

GHG Protocol · 1 control

  • GHG-Suite-Corporate-Principles GHG Protocol Suite, Corporate Standard and 5 Reporting Principles
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics

HITECH Act · 1 control

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • 62351-14 Cyber security event logging

ISMAP (Japan) · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-8.4 Logging and monitoring
  • MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP115-2 Review Techniques - Documentation, Logs, Rulesets, Configurations

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-4 Security Status Reporting and Risk Score Aggregation

NIST SP 800-144 · 1 control

  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • ORANWG11-7 Logging, Monitoring, Incident Response, and Denial-of-Service Resilience

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

OpenSSF Scorecard · 1 control

  • OSSFSC-7 Webhook Authentication, Contributors Diversity, Aggregate Score

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 44 it maps to, and the evidence behind each claim, over MCP and REST.