Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36282 | SRG-APP-102-MDM-247-SRV | SV-47686r1_rule | High |
Description |
---|
MDM server auditing capability is critical for accurate forensic analysis. The ability to transfer audit logs often is necessary to quickly isolate them, protect their integrity, and analyze their contents. An important aspect of security is maintaining awareness of what users have tried to do to with their devices. |
STIG | Date |
---|---|
Mobile Device Manager Security Requirements Guide | 2013-01-24 |
Check Text ( C-44522r1_chk ) |
---|
Verify the audit logs can be transferred from the MDM server to a storage location other than the MDM server itself. The systems administrator of the device may demonstrate this capability using an audit management application or other means. Audit records will be logged on the device for various actions especially those related to sensitive or potentially suspicious activities. The specific events to log and the information recorded for each will be a function of policy. If audit logs cannot be transferred on request or on a periodic schedule, this is a finding. |
Fix Text (F-40812r1_fix) |
---|
Configure the MDM server to support the transfer of audit logs to remote log or management servers. |