Finally, though logging and alerting have great utility, IA controls can be defeated if the alerts themselves are not managed properly or contain too much data. Thus, the SRG requires that the app must not include sensitive information in system logs, nor must it transmit error messages to any entity other than the MDM, authorized audit logs, or the actual device's display