OWASP Top 10: #9 Components with Known Vulnerabilities and #10 Insufficient Logging and Monitoring
27mIntermediate2019-10-02
Authors

Caroline Wong
Vice President of Cobalt.io
Course details
The Open Web Application Security Project (OWASP) was formed to provide the public with the resources needed to understand and enhance software security. The OWASP Top 10 list describes the ten biggest vulnerabilities. In this course, Caroline Wong takes a deep dive into the ninth and tenth categories of security vulnerabilities in the OWASP Top 10: using components with known vulnerabilities and insufficient logging and monitoring. Caroline covers how these threats work, providing real-world examples that demonstrate how insufficient logging and monitoring and using components with known vulnerabilities can affect companies and consumers alike. She also shares techniques that can help you prevent attacks stemming from these issues.
Skills covered
Application SecurityVulnerability ManagementCybersecurityDeep Dive (X:Y)
Concepts
Introduction
- Prevent common software vulnerabilities
Using Components with Known Vulnerabilities - How Does It Work
- General concept
Impact of Using Components with Known Vulnerabilities
- Example scenario 1
- Example scenario 2
Preventing Using Components with Known Vulnerabilities
- Continuously inventory and monitor
- Apply virtual patches
Insufficient Logging and Monitoring - How Does It Work
- General concept
Impact of Insufficient Logging and Monitoring
- Example scenario 1
- Example scenario 2
Preventing Insufficient Logging and Monitoring
- Ensure logs have sufficient user context
- Ensure timely detection and response
- Establish an incident response plan
Conclusion
- Next steps