Check: BUEM-00-000110
      
      
        
  BlackBerry UEM STIG:
  BUEM-00-000110
  
    (in versions v2 r1 through v1 r1)
  
      
      
    
  Title
The BlackBerry UEM server must be configured to communicate the following commands to the MDM Agent: read audit logs kept by the MD. (Cat II impact)
Discussion
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. For audit logs to be useful, administrators must have the ability to view them. SFR ID: FMT_SMF.1.1(1) #19
Check Content
Verify each Android device being managed by UEM has been configured to enable device auditing. Verify the policy pushed by UEM to each Android device include "Enable auditing". If auditing has not been enabled for each Android device being managed by UEM, this is a finding.
Fix Text
This requirement is only applicable on Android devices and is configured via each Android device STIG (enabling device Auditing). Enable device auditing for each Android device being managed by UEM using procedures in the Android STIG.
Additional Identifiers
Rule ID: SV-224372r604136_rule
Vulnerability ID: V-224372
Group Title: PP-MDM-411009
Expert Comments
      
        
        
      
      
        
  CCIs
      
      
        
        
      
    
  | Number | Definition | 
|---|---|
| CCI-000366 | Implement the security configuration settings. | 
      
        
        
      
      
        
  Controls
      
      
        
        
      
    
  | Number | Title | 
|---|---|
| CM-6 | Configuration Settings |