The UEM Agent must be configured to enable the following function: read audit logs of the managed endpoint device.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-234237
SRG-APP-000089-UEM-100012
SV-234237r617354_rule
Medium
Description
Audit logs and alerts enable monitoring of security-relevant events and subsequent forensics when breaches occur. They help identify when the security posture of the device is not as expected. This enables the UEM administrator to take an appropriate remedial action.
Satisfies: FMT_SMF_EXT.4.1
Reference: PP-UEM-401005