STIGQter STIGQter: STIG Summary: Tanium 7.x Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The Tanium application database must be dedicated to only the Tanium application.

DISA Rule

SV-253833r997260_rule

Vulnerability Number

V-253833

Group Title

SRG-APP-000323

Rule Version

TANS-DB-000002

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Move the Tanium database from the server hosting multiple databases for products other than Tanium or remove other product databases co-located with Tanium database(s).

Check Contents

With the Tanium system administrator's assistance, access the server on which the Tanium database(s) is installed.

1. Access the Tanium Server.

2. Log on to each Tanium Application Server with an account that has administrative privileges.

3. Verify SQL Server Services are not running on both servers.

If SQL Server Services are running on either server, this is a finding.

Review the Tanium database(s). If databases related to products other than Tanium exist in the Tanium database, this is a finding.

Vulnerability Number

V-253833

Documentable

False

Rule Version

TANS-DB-000002

Severity Override Guidance

With the Tanium system administrator's assistance, access the server on which the Tanium database(s) is installed.

1. Access the Tanium Server.

2. Log on to each Tanium Application Server with an account that has administrative privileges.

3. Verify SQL Server Services are not running on both servers.

If SQL Server Services are running on either server, this is a finding.

Review the Tanium database(s). If databases related to products other than Tanium exist in the Tanium database, this is a finding.

Check Content Reference

M

Target Key

5476