Check: GOOG-10-005505
Google Android 10.x STIG:
GOOG-10-005505
(in versions v2 r1 through v1 r1)
Title
Google Android 10 must be configured to enable audit logging. (Cat II impact)
Discussion
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. To be useful, Administrators must have the ability to view the audit logs. SFR ID: FMT_SMF_EXT.1.1 #32
Check Content
Review documentation on the Google Android device and inspect the configuration on the Google Android device to enable audit logging. This validation procedure is performed on only on the MDM Administration Console. On the MDM console, do the following: 1. Open the User restrictions. 2. Open user settings. 3. Select "Enable security logging". 4. Select "Enable network logging". If the MDM console device policy is not set to enable audit logging, this is a finding.
Fix Text
Configure the Google Android 10 to enable audit logging. On the MDM console: 1. Open the User restrictions. 2. Open user settings. 3. Select "Enable security logging". 4. Select "Enable network logging".
Additional Identifiers
Rule ID: SV-237018r852652_rule
Vulnerability ID: V-237018
Group Title: PP-MDF-302370
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
CCI-000370 |
The organization employs automated mechanisms to centrally manage configuration settings for organization-defined information system components. |
CCI-001851 |
The information system off-loads audit records per organization-defined frequency onto a different system or media than the system being audited. |