OWASP Top 10:2025
Logging and Monitoring

OWASP Top 10:2025 OWASPTOP10-9: A09:2025 Security Logging and Monitoring Failures

Address OWASP Top 10 A09 Security Logging and Monitoring Failures per OWASP Top 10:2025. Security Logging and Monitoring Failures arise from insufficient logging + monitoring + alerting + and incident response capability including missing audit logs + missing anomaly detection + missing incident response readiness + log injection + and information exposure via error messages. Mitigations include (a) log security-relevant events including authentication + authorisation + administrative actions + with sufficient context + (b) protect log integrity + confidentiality + availability + (c) integrate with SIEM + monitoring + alerting + (d) implement anomaly detection + incident response workflows + (e) handle errors without leaking sensitive information + (f) maintain retention aligned to regulatory + investigative + governance requirements + (g) protect against log injection.

What else in your programme already covers this

This control maps to 136 controls across 92 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-6 Reasonable Security Practices and Incident Response
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements

FedRAMP Rev 5 · 3 controls

  • 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process
  • 3.6 Encrypt Data on End-User Devices
  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.

OSFI B-13 · 3 controls

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination
  • OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity

FISMA · 2 controls

GLBA · 2 controls

HITECH Act · 2 controls

ISO/IEC 30111:2019 · 2 controls

Indonesia PDP Law · 2 controls

MARS-E · 2 controls

MTCS (Singapore) · 2 controls

Malaysia PDPA 2010 · 2 controls

NIST SP 800-171 · 2 controls

  • 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process
  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

Open Banking Security · 2 controls

  • OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

South Korea PIPA · 2 controls

  • 4.4.7 Emergency and Incident Response

FDA 21 CFR Part 11 · 1 control

  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

GHG Protocol · 1 control

HKMA SPM · 1 control

IEEE 1686 · 1 control

ISMAP (Japan) · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

ISO/IEC 29147:2018 · 1 control

India DPDP Act · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NAIC-2 Information Security Program (ISP) - Section 4

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP115-2 Review Techniques - Documentation, Logs, Rulesets, Configurations

NIST SP 800-122 · 1 control

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-4 Security Status Reporting and Risk Score Aggregation

NIST SP 800-144 · 1 control

  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

NIST SP 800-61 · 1 control

  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN
  • ORANWG11-7 Logging, Monitoring, Incident Response, and Denial-of-Service Resilience

OWASP ASVS · 1 control

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification

OpenSSF Scorecard · 1 control

  • OSSFSC-7 Webhook Authentication, Contributors Diversity, Aggregate Score
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 136 it maps to, and the evidence behind each claim, over MCP and REST.