Information Gathering -> Logging: PII logging concept
Risk and Opportunity
Risk: Personal identifiable information (PII) is logged and the law of GDPR is not followed.
Opportunity: A concept how to log PII is documented and applied.
- rsyslog, Link, Tags: tool logging
- logstash, Link, Tags: tool logging
- fluentd, , Tags: tool
- bash, , Tags: tool
Usefulness and Requirements of this Activity
Usefullness: Very Low
Required knowledge: Very Low (one discipline)
Required time: Very Low
Required resources (systems): Very Low
OWASP SAMM VERSION 2
- not explicitly covered by ISO 27001 - too specific