STIGQter STIGQter: STIG Summary: Tanium 7.x Operating System on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

The Tanium Operating System (TanOS) must synchronize internal information system clocks to the authoritative time source when the time difference is greater than the organization-defined time period.

DISA Rule

SV-254866r1067750_rule

Vulnerability Number

V-254866

Group Title

SRG-OS-000356

Rule Version

TANS-OS-001100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "A" for "Appliance Configuration Menu," and then press "Enter".

4. Press "3" for "NTP Configuration," and then press "Enter".

5. Type "Yes" to "Remove the current NTP servers and enter new information?" and then press "Enter".

6. Type the first NTP server address and then press "Enter".

7. Type "Yes" to provide a second NTP Server, and then press "Enter".

8. Type the second NTP server address and then press "Enter".

9. Press "Enter" to return to the "Appliance Configuration" menu.

Check Contents

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "A" for "Appliance Configuration Menu," and then press "Enter".

4. Press "3" for "NTP Configuration," and then press "Enter".

If there is no address listed for "Currently configured ntp servers:", this is a finding.

The status is reported differently in different versions of TanOS.

TanOS <= 1.7.1:
If the "Current NTP Status" does not list a status of "Synchronized to NTP Server (
) at stratum #" and "Time correct to within # ms", this is a finding.

TanOS >= 1.7.2:
If the "Current NTP Status" does not list a status of "Normal", this is a finding.

Vulnerability Number

V-254866

Documentable

False

Rule Version

TANS-OS-001100

Severity Override Guidance

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "A" for "Appliance Configuration Menu," and then press "Enter".

4. Press "3" for "NTP Configuration," and then press "Enter".

If there is no address listed for "Currently configured ntp servers:", this is a finding.

The status is reported differently in different versions of TanOS.

TanOS <= 1.7.1:
If the "Current NTP Status" does not list a status of "Synchronized to NTP Server (
) at stratum #" and "Time correct to within # ms", this is a finding.

TanOS >= 1.7.2:
If the "Current NTP Status" does not list a status of "Normal", this is a finding.

Check Content Reference

M

Target Key

5491