Check: GOOG-10-006100
Google Android 10.x STIG:
GOOG-10-006100
(in versions v2 r1 through v1 r1)
Title
Google Android 10 must be configured to generate audit records for the following auditable events: detected integrity violations. (Cat III impact)
Discussion
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify attacks so that breaches can either be prevented or limited in their scope. They facilitate analysis to improve performance and security. The Requirement Statement lists key events that the system must generate an audit record for. Application note: Requirement applies only to integrity violation detections that can be logged by the audit logging component. SFR ID: FMT_SMF_EXT.1.1 #37
Check Content
Review Google Android device configuration settings to determine if the mobile device is configured to generate audit records for the following auditable events: detected integrity violations. This validation procedure is performed only on the MDM Administration Console. On the MDM console, do the following: 1. Go to Policy management. 2. Confirm Security Logging is enabled. If the MDM console device policy is not set to enable security logging, this is a finding.
Fix Text
Configure the Google Android device to generate audit records for the following auditable events: detected integrity violations. On the MDM console, do the following: On the MDM Console: 1. Go to Policy management. 2. Enable Security Logging.
Additional Identifiers
Rule ID: SV-237019r639203_rule
Vulnerability ID: V-237019
Group Title: PP-MDF-301420
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000169 |
The information system provides audit record generation capability for the auditable events defined in AU-2 a. at organization-defined information system components. |
Controls
Number | Title |
---|---|
AU-12 |
Audit Generation |