UCF STIG Viewer Logo

The MDM server must support the transfer of audit logs to remote log or management servers.


Overview

Finding ID Version Rule ID IA Controls Severity
V-36282 SRG-APP-102-MDM-247-SRV SV-47686r1_rule High
Description
MDM server auditing capability is critical for accurate forensic analysis. The ability to transfer audit logs often is necessary to quickly isolate them, protect their integrity, and analyze their contents. An important aspect of security is maintaining awareness of what users have tried to do to with their devices.
STIG Date
Mobile Device Manager Security Requirements Guide 2013-01-24

Details

Check Text ( C-44522r1_chk )
Verify the audit logs can be transferred from the MDM server to a storage location other than the MDM server itself. The systems administrator of the device may demonstrate this capability using an audit management application or other means. Audit records will be logged on the device for various actions especially those related to sensitive or potentially suspicious activities. The specific events to log and the information recorded for each will be a function of policy. If audit logs cannot be transferred on request or on a periodic schedule, this is a finding.
Fix Text (F-40812r1_fix)
Configure the MDM server to support the transfer of audit logs to remote log or management servers.