STIGUI
V-284810CAT II — Medium severitySV-284810r1240404_rule

Google Android 17 must be configured to enable audit logging.

Rule version GOOG-17-006600 · STIG v1 · 2026-07-09

Discussion

Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. For the audit logs to be useful, administrators must have the ability to view them.

SFR ID: FMT_SMF.1.1_EXT1.1 #32

Check

Inspect the configuration on the managed Google Android 17 device to enable audit logging.

This validation procedure is performed only on the EMM administration console.

On the EMM console:

COBO and COPE:

1. Open the "Device owner management" section. 2. Verify that "Enable security logging" is toggled to "ON".

If the EMM console device policy is not set to enable audit logging, this is a finding.

Fix

Configure the Google Android 17 device to enable audit logging.

On the EMM console:

COBO and COPE:

1. Open the "Device owner management" section. 2. Toggle "Enable security logging" to "ON".

Configuration API: setSecurityLoggingEnabled

Identifiers

Group ID
V-284810
Group title
PP-MDF-401630
Rule ID
SV-284810r1240404_rule
Check ID
C-89380r1240403_chk
Fix ID
F-89285r1240136_fix