STIGQter STIGQter: STIG Summary: Tanium 7.3 Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 20 Feb 2019: Firewall rules must be configured on the Tanium Server for Console-to-Server communications.

DISA Rule

SV-102187r1_rule

Vulnerability Number

V-92085

Group Title

SRG-APP-000383

Rule Version

TANS-CN-000014

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure host-based firewall rules on the Tanium Server to include the following required traffic:

Allow TCP traffic on port 433 to the Tanium Server from designated Tanium console user clients.

Configure the network firewall to allow the above traffic.

Check Contents

Consult with the Tanium System Administrator to verify which firewall is being used as a host-based firewall on the Tanium Server.

Access the host-based firewall configuration on the Tanium Server.

Validate a rule exists for the following:
Port Needed: From only designated Tanium console user clients to Tanium Server over TCP port 443.

If a host-based firewall rule does not exist to allow only designated Tanium console user clients to Tanium Server over TCP port 443, this is a finding.

Consult with the network firewall administrator and validate rules exist for the following:
Allow TCP traffic from only designated Tanium console user clients to Tanium Server over TCP ports 443.

If a network firewall rule does not exist to allow traffic from only designated Tanium console user clients to Tanium Server over TCP port 443, this is a finding.

Vulnerability Number

V-92085

Documentable

False

Rule Version

TANS-CN-000014

Severity Override Guidance

Consult with the Tanium System Administrator to verify which firewall is being used as a host-based firewall on the Tanium Server.

Access the host-based firewall configuration on the Tanium Server.

Validate a rule exists for the following:
Port Needed: From only designated Tanium console user clients to Tanium Server over TCP port 443.

If a host-based firewall rule does not exist to allow only designated Tanium console user clients to Tanium Server over TCP port 443, this is a finding.

Consult with the network firewall administrator and validate rules exist for the following:
Allow TCP traffic from only designated Tanium console user clients to Tanium Server over TCP ports 443.

If a network firewall rule does not exist to allow traffic from only designated Tanium console user clients to Tanium Server over TCP port 443, this is a finding.

Check Content Reference

M

Target Key

3505

Comments