Google Android 13 must be configured to enable audit logging.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
|---|---|---|---|---|---|---|
| medium | V-254733 | PP-MDF-990000 | GOOG-13-002800 | SV-254733r959010_rule | 2024-12-04 | 2 |
Description
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. To be useful, administrators must have the ability to view the audit logs.
SFR ID: FMT_SMF_EXT.1.1 #32
ℹ️ Check
Inspect the configuration on the managed Google Android 13 device to enable audit logging.
This validation procedure is performed only on the EMM Administration Console.
On the EMM console:
COBO and COPE:
1. Open "Device owner management" section.
2. Verify that "Enable security logging" is toggled to "ON".
If the EMM console device policy is not set to enable audit logging, this is a finding.
✔️ Fix
Configure the Google Android 13 device to enable audit logging.
On the EMM console:
COBO and COPE:
1. Open "Device owner management" section.
2. Toggle "Enable security logging" to "ON".