Frameworks / OWASP Top 10:2025 / OWASPTOP10-9 OWASP Top 10:2025
Logging and Monitoring
OWASP Top 10:2025 OWASPTOP10-9: A09:2025 Security Logging and Monitoring Failures Address OWASP Top 10 A09 Security Logging and Monitoring Failures per OWASP Top 10:2025. Security Logging and Monitoring Failures arise from insufficient logging + monitoring + alerting + and incident response capability including missing audit logs + missing anomaly detection + missing incident response readiness + log injection + and information exposure via error messages. Mitigations include (a) log security-relevant events including authentication + authorisation + administrative actions + with sufficient context + (b) protect log integrity + confidentiality + availability + (c) integrate with SIEM + monitoring + alerting + (d) implement anomaly detection + incident response workflows + (e) handle errors without leaking sensitive information + (f) maintain retention aligned to regulatory + investigative + governance requirements + (g) protect against log injection.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 132 controls across 88 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-6 Reasonable Security Practices and Incident Response NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests FedRAMP-IncidentReporting FedRAMP incident reporting to PMO and US-CERT GhCSA-Cybercrime-Lawful-Access-Preservation Cybercrime Offences, Lawful Access and Electronic Evidence Preservation GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200 FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) GLBA-Implementation-Roadmap-Examination GLBA Implementation Roadmap, Examination Readiness, Roles and Tooling GLBA-Status-FTC-CFPB-SEC-NAIC-Enforcement GLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors 30111-3 Terms and definitions 30111-5.2 Vulnerability handling team MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-Security-Principle-Retention-Data-Integrity-Breach-Notification-72-Hour-Section-12B-2024-Amendment Malaysia PDPA Security + Retention + Data Integrity + Breach Notification 72 Hour + Section 12B + 2024 Amendment NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-6 Reasonable Data Security and Incident Response DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25 4.4.7 Emergency and Incident Response LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e)) FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis) FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) GHG-Suite-Corporate-Principles GHG Protocol Suite, Corporate Standard and 5 Reporting Principles GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF 62351-14 Cyber security event logging IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills 27010-16.1 Continuity of Sharing 27011-8.4 Logging and monitoring 27400-6.5 Security monitoring and incident response INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response LAOS-CC-LaoCERT-Incident-Response-National-Cybersecurity-Coordination-Article-22 Laos Cybercrime LaoCERT + Incident Response + National Cybersecurity Coordination + Article 22 DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training MAS-TRM-Cyber-Resilience-Chapter-11-Threat-Intelligence-Penetration-Testing-Incident-Response-1-Hour-Notification MAS TRM Cyber Resilience + Chapter 11 + Threat Intelligence + Penetration Testing + Incident Response + 1-Hour Notification MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In NAIC-2 Information Security Program (ISP) - Section 4 NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP115-2 Review Techniques - Documentation, Logs, Rulesets, Configurations NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup NISTSP137-4 Security Status Reporting and Risk Score Aggregation NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation NHPA-6 Reasonable Data Security and Breach Response NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN ORANWG11-7 Logging, Monitoring, Incident Response, and Denial-of-Service Resilience OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification OSSFSC-7 Webhook Authentication, Contributors Diversity, Aggregate Score OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 132 it maps to, and the evidence behind each claim, over MCP and REST.