Samsung Android must be configured to enable the Knox audit log.
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify attacks so that breaches can be prevented or limited in their scope, and they facilitate analysis to improve performance and security. The requirement statement lists key events for which the system must generate an audit record.
SFR ID: FAU_GEN.1.1 #8