Exposure of sensitive information in logs

Overview

Sensitive information should never be included in logs. While logging all information may be helpful during development, it's important to make sure that any sensitive user data and system information are not accidentally exposed. Debug logs should not contain any sensitive data such as usernames, passwords, contact information, PII, etc.).

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Frequent

Incidence

How common is this issue?
29%16%
arrow down13%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
2 years6 months
arrow down70%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconData SecurityiconSharing and VisibilityiconA02:2021 – Cryptographic Failuresicon