Google Android 16 must be configured to enable audit logging.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-276850PP-MDF-993300GOOG-16-002800SV-276850r1140342_rule2025-09-181
Description
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. For the audit logs to be useful, administrators must have the ability to view them. SFR ID: FMT_SMF.1.1 #32
ℹ️ Check
Inspect the configuration on the managed Google Android 16 device to enable audit logging. This validation procedure is performed only on the EMM Administration Console. On the EMM console: COBO and COPE: 1. Open "Device owner management" section. 2. Verify that "Enable security logging" is toggled to "ON". If the EMM console device policy is not set to enable audit logging, this is a finding.
✔️ Fix
Configure the Google Android 16 device to enable audit logging. On the EMM console: COBO and COPE: 1. Open "Device owner management" section. 2. Toggle "Enable security logging" to "ON". Configuration API: setSecurityLoggingEnabled