Google Android 15 must be configured to enable audit logging.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-267430GOOG-15-002800SV-267430r1031475_ruleCCI-000154medium
Description
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. To be useful, administrators must have the ability to view the audit logs. SFRID: FMT_SMF.1.1 #32
STIGDate
Google Android 15 COBO Security Technical Implementation Guide2024-12-05

Details

Check Text (C-267430r1031475_chk)

Inspect the configuration on the managed Google Android 15 device to enable audit logging. This validation procedure is performed only on the EMM Administration Console. On the EMM console: COBO and COPE: 1. Open "Device owner management" section. 2. Verify that "Enable security logging" is toggled to "ON". If the EMM console device policy is not set to enable audit logging, this is a finding.

Fix Text (F-71257r1031474_fix)

Configure the Google Android 15 device to enable audit logging. On the EMM console: COBO and COPE: 1. Open "Device owner management" section. 2. Toggle "Enable security logging" to "ON".