SV-253824r997258_rule
V-253824
SRG-APP-000108
TANS-CN-000016
CAT II
10
1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web UI and log on with multifactor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Connect".
4. Expand the left menu.
5. Click "Connections".
6. Configure a Connection for the "Tanium Audit Source" source from the Tanium Application to a SIEM tool.
Work with the SIEM administrator to configure an alert when no audit data is received from Tanium based on the defined schedule of connections.
1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web user interface (UI) and log on with multifactor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Connect".
4. Review the configured Connections under "Connections" section.
Work with the security information and event management (SIEM) administrator to determine if an alert is configured when audit data is no longer received as expected.
If no alert is configured, this is a finding.
V-253824
False
TANS-CN-000016
1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web user interface (UI) and log on with multifactor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Connect".
4. Review the configured Connections under "Connections" section.
Work with the security information and event management (SIEM) administrator to determine if an alert is configured when audit data is no longer received as expected.
If no alert is configured, this is a finding.
M
5476