ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsHard

A company's security team is performing a review of their logging infrastructure. They discover that while operating system logs are being collected, application-level logs for their custom-built CRM system are largely disabled by default. The CRM system handles highly sensitive customer data. What is the MOST significant risk introduced by this lack of application-level logging?

  1. AFailure to meet regulatory compliance requirements for network traffic monitoring.
  2. BDifficulty in identifying and tracing specific data breaches or unauthorized data access within the CRM application.
  3. CReduced system performance due to the overhead of OS-level logging.
  4. DIncreased storage costs due to excessive operating system logs.
Show answer & explanation

Correct answer: B. Difficulty in identifying and tracing specific data breaches or unauthorized data access within the CRM application.

Application-level logs provide granular details about user actions, data access, and internal application events. Without these, it becomes extremely difficult to pinpoint the exact actions leading to a data breach within the application, track unauthorized access to sensitive data, or perform detailed forensic analysis of application-specific incidents, which is a significant operational and compliance risk.

Why the other options are wrong

  • A. Regulatory compliance often requires auditing of data access, which relies heavily on application-level logs, but 'network traffic monitoring' is distinct from application-specific event logging.
  • C. OS-level logging can have overhead, but the question is about the *lack* of application logging, not the overhead of OS logging.
  • D. While OS logs can be voluminous, the lack of *application* logs doesn't directly *increase* OS log storage costs; it's a separate concern.

Application Logging Importance

Application logging records events and activities specific to a software application, such as user logins, data access, transactions, and errors. These logs are critical for security monitoring, forensic analysis, auditing, and troubleshooting application-specific issues.

  • Provides granular detail on internal application events.
  • Essential for auditing user actions and data access.
  • Crucial for forensic investigations of application breaches.
  • Often required for regulatory compliance.

Memory trick: OS is the house, App is the room.

More Security Operations questions