Free DISA STIG and SRG Library | Vaulted

V-228592

Google Android 11 must be configured to enable audit logging.

Finding ID
GOOG-11-005505
Rule ID
SV-228592r510289_rule
Severity
Cat II
CCE
(None)
Group Title
PP-MDF-302370
CCI
CCI-001851
Target Key
(None)
Documentable
No
Discussion

Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. To be useful, Administrators must have the ability to view the audit logs. SFR ID: FMT_SMF_EXT.1.1 #32

Fix Text

Configure the Google Android 11 device to enable audit logging. On the EMM console: 1. Open "Device owner management" section. 2. Toggle "Enable security logging" to On.

Check Content

Review documentation on the Google Android device and inspect the configuration on the Google Android device to enable audit logging. This validation procedure is performed on only on the EMM Administration Console. On the EMM console, do the following: 1. Open "Device owner management" section. 2. Verify that "Enable security logging" is toggled to On. If the EMM console device policy is not set to enable audit logging, this is a finding.