OWASP Top 10:2025
Logging and Monitoring

OWASP Top 10:2025 9: A09:2025 Security Logging and Monitoring Failures

Address OWASP Top 10 A09 Security Logging and Monitoring Failures per OWASP Top 10:2025. Security Logging and Monitoring Failures arise from insufficient logging + monitoring + alerting + and incident response capability including missing audit logs + missing anomaly detection + missing incident response readiness + log injection + and information exposure via error messages. Mitigations include (a) log security-relevant events including authentication + authorisation + administrative actions + with sufficient context + (b) protect log integrity + confidentiality + availability + (c) integrate with SIEM + monitoring + alerting + (d) implement anomaly detection + incident response workflows + (e) handle errors without leaking sensitive information + (f) maintain retention aligned to regulatory + investigative + governance requirements + (g) protect against log injection.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.