This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

H10. Be vigilant and on alert

From OWASP
Jump to: navigation, search


H10. Be vigilant and on alert

Description: In the real world, being on alert is important. Hearing and investigating the strange noise your car is making now can save money in repairs later. Ignoring it could result in a car that is unsafe to drive. In the digital world, dismissing alerts and notification, casually responding to web page alerts, etc. can result in the compromise of your accounts, systems, and/or data. Learning what to be aware of and how to react (if at all) is important.

Threats: Missing early signs of possible security situations when they are preventable or limited in scope.

Impact: Increased damage, data exposure, or compromise.

Recommendations:

Consumers should focus on:

1. Think through online/digital activities and compare them to what you would do in the “real world”
2. Use account monitoring services
3. Review online account activity

Tech-savvy users should also:

1. Beware of tech-support scammers
2. Be savvy on client-side and social engineering attacks
3. Use credit monitoring and freeze, and similar services to protect your credit

Example: Ignoring a web page that says you last logged in 2 hours ago from New York when you are in Seattle and haven’t left the state in a year may be an indicator of breaches to come if you don’t take corrective action.