#3963·mastg

Update MASTG-KNOW-0049 and MASTG-BEST-0002 for Android logging

Author: dchapagainCreated Sep 12, 2026Updated Sep 13, 2026

Following discussion #3948 and issue #3949, this issue tracks the documentation scope confirmed in this comment.

Scope

MASTG-KNOW-0049

  • Expand the Android logging article to a similar level of coverage as MASTG-KNOW-0101.
  • Cover Android logging APIs and mechanisms, including NDK logging, logcat behavior, log levels and tags, and the access model.
  • Document what Android's logging APIs do and don't provide for privacy, contrasted with Apple's Unified Logging privacy model.
  • Cover Slog, EventLog, third-party logging facades, and other relevant logging paths.
  • Remove threat and remediation language so the KNOW content is descriptive.

MASTG-BEST-0002

  • Align the guidance with Android's Log Info Disclosure documentation.
  • Add R8 coverage alongside the existing ProGuard guidance, which currently does not cover R8.
  • Add log-level management, toString() sanitization, redaction and masking, compile-time constants, and incident-response guidance.
  • Retain the existing StringBuilder caveat.

The MASTG-DEMO-0006 update remains tracked separately in #3949.

Open Question

MASTG-BEST-0002 is currently titled "Remove Logging Code" with alias: remove-logging-code. Since the expanded guidance also covers redaction, masking, and log-level management, should the title and alias remain unchanged, or should they be updated as part of this work?

A draft PR for the KNOW and BEST documentation updates will follow shortly.

Please assign this issue to @dchapagain.