Rule ID
SV-235080r852714_rule
Version
V1R2
CCIs
CCI-000366, CCI-000370, CCI-001851
Audit logs enable monitoring of security-relevant events and subsequent forensics when breaches occur. To be useful, Administrators must have the ability to view the audit logs. SFR ID: FMT_SMF_EXT.1.1 #32
Review documentation on the Honeywell Android device and inspect the configuration on the Honeywell Android device to enable audit logging. This validation procedure is performed on only on the MDM Administration console. On the MDM console: 1. Open the Restrictions settings. 2. Open User settings. 3. Select "Enable security logging". 4. Select "Enable network logging". If the MDM console device policy is not set to enable audit logging, this is a finding.
Configure the Honeywell Android Pie to enable audit logging. On the MDM console: 1. Open the Restrictions settings. 2. Open User settings. 3. Select "Enable security logging". 4. Select "Enable network logging".