STIGQter STIGQter: STIG Summary: Tanium 7.x Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The Tanium Server must be configured to allow only signed content to be imported.

DISA Rule

SV-253846r1067667_rule

Vulnerability Number

V-253846

Group Title

SRG-APP-000131

Rule Version

TANS-SV-000015

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Contact Tanium for a corrected license file.

1. Double-click the new "tanium.license" file and select Notepad to open the file.

2. Select "Edit" and then select "Find" from the menu in Notepad.

3. Type "allow_unsigned_import" in the search box and select "Find Next".

4. Verify "allow_unsigned_import" is followed by ":false".

5. Upload the "tanium.license" file to the Tanium Server.

6. Apply the corrected license file.

Check Contents

Note: This requirement applies only to Tanium implementations in production. If implementation being evaluated is in development, this requirement is not applicable.

1. Access the Tanium Server through interactive logon.

2. Open Windows Explorer and browse to the installation drive of the Tanium Server (e.g., E:\Program Files\Tanium\Tanium Server).

3. Locate the "tanium.license" file and double-click it.

4. Select "Notepad' to open the "tanium.license" file.

5. Select "Edit" and then select "Find" from the menu in Notepad.

6. Type "allow_unsigned_import" in the search box and select "Find Next."

If "allow_unsigned_import" is followed by ":true", this is a finding.

If "allow_unsigned_import" is followed by ":false", this is not a finding.

Vulnerability Number

V-253846

Documentable

False

Rule Version

TANS-SV-000015

Severity Override Guidance

Note: This requirement applies only to Tanium implementations in production. If implementation being evaluated is in development, this requirement is not applicable.

1. Access the Tanium Server through interactive logon.

2. Open Windows Explorer and browse to the installation drive of the Tanium Server (e.g., E:\Program Files\Tanium\Tanium Server).

3. Locate the "tanium.license" file and double-click it.

4. Select "Notepad' to open the "tanium.license" file.

5. Select "Edit" and then select "Find" from the menu in Notepad.

6. Type "allow_unsigned_import" in the search box and select "Find Next."

If "allow_unsigned_import" is followed by ":true", this is a finding.

If "allow_unsigned_import" is followed by ":false", this is not a finding.

Check Content Reference

M

Target Key

5476