STIGQter STIGQter: STIG Summary: Tanium 7.x Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The Tanium application must alert the information system security officer and system administrator (at a minimum) in the event of an audit processing failure.

DISA Rule

SV-253824r997258_rule

Vulnerability Number

V-253824

Group Title

SRG-APP-000108

Rule Version

TANS-CN-000016

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web UI and log on with multifactor authentication.

2. Click "Modules" on the top navigation banner.

3. Click "Connect".

4. Expand the left menu.

5. Click "Connections".

6. Configure a Connection for the "Tanium Audit Source" source from the Tanium Application to a SIEM tool.

Work with the SIEM administrator to configure an alert when no audit data is received from Tanium based on the defined schedule of connections.

Check Contents

1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web user interface (UI) and log on with multifactor authentication.

2. Click "Modules" on the top navigation banner.

3. Click "Connect".

4. Review the configured Connections under "Connections" section.

Work with the security information and event management (SIEM) administrator to determine if an alert is configured when audit data is no longer received as expected.

If no alert is configured, this is a finding.

Vulnerability Number

V-253824

Documentable

False

Rule Version

TANS-CN-000016

Severity Override Guidance

1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web user interface (UI) and log on with multifactor authentication.

2. Click "Modules" on the top navigation banner.

3. Click "Connect".

4. Review the configured Connections under "Connections" section.

Work with the security information and event management (SIEM) administrator to determine if an alert is configured when audit data is no longer received as expected.

If no alert is configured, this is a finding.

Check Content Reference

M

Target Key

5476