STIGQter STIGQter: STIG Summary: Tanium 7.x Operating System on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

The Tanium operating system (TanOS) must, for networked systems, compare internal information system clocks at least every 24 hours with a server synchronized to one of the redundant United States Naval Observatory (USNO) time servers or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).

DISA Rule

SV-254865r1067747_rule

Vulnerability Number

V-254865

Group Title

SRG-OS-000355

Rule Version

TANS-OS-001095

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "A" for "Appliance Configuration Menu," and then press "Enter".

4. Press "3" for "NTP Configuration," and then press "Enter".

5. Type "Yes" to "Remove the current NTP servers and enter new information?" and then press "Enter".

6. Type the first NTP server address and then press "Enter".

7. Type "Yes" to provide a second NTP Server, and then press "Enter".

8. Type the second NTP server address and then press "Enter".

9. Press "Enter" to return to the "Appliance Configuration" menu.

Check Contents

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "A" for "Appliance Configuration Menu," and then press "Enter".

4. Press "3" for "NTP Configuration," and then press "Enter".

If there is no address listed for "Currently configured ntp servers:", this is a finding.

The status is reported differently in different versions of TanOS.

TanOS <= 1.7.1:
If the "Current NTP Status" does not list a status of "Synchronized to NTP Server (
) at stratum #" and "Time correct to within # ms", this is a finding.

TanOS >= 1.7.2:
If the "Current NTP Status" does not list a status of "Normal", this is a finding.

Vulnerability Number

V-254865

Documentable

False

Rule Version

TANS-OS-001095

Severity Override Guidance

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "A" for "Appliance Configuration Menu," and then press "Enter".

4. Press "3" for "NTP Configuration," and then press "Enter".

If there is no address listed for "Currently configured ntp servers:", this is a finding.

The status is reported differently in different versions of TanOS.

TanOS <= 1.7.1:
If the "Current NTP Status" does not list a status of "Synchronized to NTP Server (
) at stratum #" and "Time correct to within # ms", this is a finding.

TanOS >= 1.7.2:
If the "Current NTP Status" does not list a status of "Normal", this is a finding.

Check Content Reference

M

Target Key

5491