Skip to main navigation Skip to search Skip to main content

A Structured Approach to Log Design: Addressing Security and Compliance Gaps in Software Development

  • University of Plymouth
  • Noroff University College
  • Nelson Mandela University

Research output: Chapter in Book/Report/Conference proceedingConference proceedings published in a bookpeer-review

Abstract

Logging is a critical yet often neglected aspect of software development, frequently implemented without adequate consideration for security, privacy, or compliance. This oversight can lead to vulnerabilities, hinder forensic investigations, and undermine regulatory obligations. This paper examines persistent deficiencies in logging practices using empirical data from a targeted developer survey, alongside analysis of OWASP Top 10 vulnerabilities and Common Weakness Enumeration (CWE) classifications. The findings reveal recurring issues, including the inadvertent exposure of sensitive data, failure to record security-critical events, and inconsistent or undocumented logging standards. Despite the central role of logs in debugging, monitoring, and incident response, many developers lack formal training and operate without clear guidelines, resulting in fragmented and insecure implementations. These insights highlight the need to treat logging as a core component of secure software development.

Original languageEnglish
Title of host publicationHuman Aspects of Information Security and Assurance - 19th IFIP WG 11.12 International Symposium, HAISA 2025, Proceedings
EditorsSteven Furnell, Nathan Clarke
PublisherSpringer Science and Business Media Deutschland GmbH
Pages362-375
Number of pages14
ISBN (Electronic)978-3-032-02504-3
ISBN (Print)9783032025036
DOIs
Publication statusE-pub ahead of print - 30 Oct 2025
Event19th IFIP WG 11.12 International Symposium on Human Aspects of Information Security and Assurance, HAISA 2025 - Mytilene, Greece
Duration: 7 Jul 20259 Jul 2025

Publication series

NameIFIP Advances in Information and Communication Technology
Volume761
ISSN (Print)1868-4238
ISSN (Electronic)1868-422X

Conference

Conference19th IFIP WG 11.12 International Symposium on Human Aspects of Information Security and Assurance, HAISA 2025
Country/TerritoryGreece
CityMytilene
Period7/07/259/07/25

ASJC Scopus subject areas

  • Information Systems and Management

Keywords

  • Developer Survey
  • Logging Design Culture
  • Privacy in Logging

Fingerprint

Dive into the research topics of 'A Structured Approach to Log Design: Addressing Security and Compliance Gaps in Software Development'. Together they form a unique fingerprint.

Cite this