STIGQter STIGQter: STIG Summary: Tanium 7.x Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The Tanium documentation identifying recognized and trusted Security Content Automation Protocol (SCAP) sources must be maintained.

DISA Rule

SV-253867r997289_rule

Vulnerability Number

V-253867

Group Title

SRG-APP-000039

Rule Version

TANS-SV-000050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the site does not have the "Tanium Comply" module or does not use "Tanium Comply" for compliance validation, this finding is not applicable.

Prepare and maintain documentation identifying the source of SCAP sources that will be used by the "Tanium Comply" module.

Check Contents

Consult with the Tanium system administrator to review the documented list of trusted SCAP sources.

If the site does not have the "Tanium Comply" module or does not use "Tanium Comply" for compliance validation, this finding is not applicable.

If the site does use Tanium Comply and the source for SCAP content is not documented, this is a finding.

Vulnerability Number

V-253867

Documentable

False

Rule Version

TANS-SV-000050

Severity Override Guidance

Consult with the Tanium system administrator to review the documented list of trusted SCAP sources.

If the site does not have the "Tanium Comply" module or does not use "Tanium Comply" for compliance validation, this finding is not applicable.

If the site does use Tanium Comply and the source for SCAP content is not documented, this is a finding.

Check Content Reference

M

Target Key

5476