STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 4 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to VMware Workspace ONE UEM Security Technical Implementation Guide

V-221651

CAT II (Medium)

The MDM Agent must be configured to enable the following function: [selection: read audit logs of the MD]. This requirement is inherently met if the function is automatically implemented during MDM Agent install/device enrollment.

Rule ID

SV-221651r960918_rule

STIG

VMware Workspace ONE UEM Security Technical Implementation Guide

Version

V2R2

CCIs

CCI-000154

Discussion

Audit logs and alerts enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify when the security posture of the device is not as expected. This enables the MDM administrator to take an appropriate remedial action. SFR ID: FMT_SMF_EXT.4.1

Check Content

Review the MDM Agent documentation and configuration settings to determine if the following function is enabled: read audit logs of the MD.

This validation procedure is performed on the MDM Administration Console.

On the MDM console, do the following:
1. Authenticate to the Workspace ONE UEM console as the administrator.
2. Navigate to Groups & Settings >> All Settings >> Devices & Users >> General >> Privacy and enable Request Device Log in the privacy settings.

If "Request Device Log" is present, then no device log is being requested from the MD and this is a finding.

Fix Text

Configure the MDM Agent to enable the following function: read audit logs of the MD.

On the MDM console, do the following:
1. Authenticate to the Workspace ONE UEM console as the administrator.
2. Navigate to Groups & Settings >> All Settings >> Devices & Users >> General >> Privacy and enable Request Device Log in the privacy settings.
3. Select "SAVE".