UCF STIG Viewer Logo

Google Android 12 must be configured to enable audit logging.


Overview

Finding ID Version Rule ID IA Controls Severity
V-250418 GOOG-12-002800 SV-250418r802621_rule Medium
Description
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. To be useful, Administrators must have the ability to view the audit logs. SFR ID: FMT_SMF_EXT.1.1 #32
STIG Date
Google Android 12 COPE Security Technical Implementation Guide 2021-09-17

Details

Check Text ( C-53853r796760_chk )
Inspect the configuration on the managed Google Android 12 device to enable audit logging.

This validation procedure is performed only on the EMM Administration Console.

On the EMM console:

COBO and COPE:

1. Open "Device owner management" section.
2. Verify that "Enable security logging" is toggled to ON.

If the EMM console device policy is not set to enable audit logging, this is a finding.
Fix Text (F-53807r796761_fix)
Configure the Google Android 12 device to enable audit logging.

On the EMM console:

COBO and COPE:

1. Open "Device owner management" section.
2. Toggle "Enable security logging" to ON.