STIGQter STIGQter: STIG Summary: Samsung Android 16 COBO Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 13 May 2026:

Samsung Android's Work profile must be configured to enable audit logging.

DISA Rule

SV-276566r1139220_rule

Vulnerability Number

V-276566

Group Title

PP-MDF-993300

Rule Version

KNOX-16-009100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Samsung Android devices' Work profile to enable audit logging. (COPE)

Configure the Samsung Android devices to enable audit logging. (COBO)

On the management tool, in the Work profile restrictions section, set "Security logging" to "Enable".

API: setSecurityLoggingEnabled

Check Contents

COPE:
Review the configuration to determine if the Samsung Android devices' Work profile is enabling audit logging.

This validation procedure is performed on the management tool only.

On the management tool, in the Work profile restrictions, verify "Security logging" is set to "Enable".

If on the management tool "Security logging" is not set to "Enable", this is a finding.

COBO:
Review the configuration to determine if the Samsung Android devices are enabling audit logging.

This validation procedure is performed on the management tool only.

On the management tool, in the device restrictions, verify "Security logging" is set to "Enable".

If on the management tool "Security logging" is not set to "Enable", this is a finding.

Vulnerability Number

V-276566

Documentable

False

Rule Version

KNOX-16-009100

Severity Override Guidance

COPE:
Review the configuration to determine if the Samsung Android devices' Work profile is enabling audit logging.

This validation procedure is performed on the management tool only.

On the management tool, in the Work profile restrictions, verify "Security logging" is set to "Enable".

If on the management tool "Security logging" is not set to "Enable", this is a finding.

COBO:
Review the configuration to determine if the Samsung Android devices are enabling audit logging.

This validation procedure is performed on the management tool only.

On the management tool, in the device restrictions, verify "Security logging" is set to "Enable".

If on the management tool "Security logging" is not set to "Enable", this is a finding.

Check Content Reference

M

Target Key

5714