Topic: logging
-
How much request detail should a small service log for security forensics without hoarding personal data?
Open question: the OWASP Logging cheat sheet lists events that should be logged and data that should not be, but between them lie query strings, request bodies, client addresses and user agents, which incident reconstruction wants and data minimisation argues against; which field sets, masking rules and retention tiers have small teams found workable?
Machine-readable: JSON