STIGQter STIGQter: STIG Summary: Tanium 7.x Operating System on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

The Tanium Operating System (TanOS) must be configured to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources.

DISA Rule

SV-254867r1015860_rule

Vulnerability Number

V-254867

Group Title

SRG-OS-000357

Rule Version

TANS-OS-001105

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "A" for "Appliance Configuration Menu," and then press "Enter".

4. Press "3" for "NTP Configuration," and then press "Enter".

5. Type "Yes" to "Remove the current NTP servers and enter new information?" and press "Enter".

6. Type the first NTP server address and press "Enter".

7. Type "Yes" to provide a second NTP Server, and then press "Enter".

8. Type the second NTP server address, and then press "Enter".

9. Press "Enter" to return to the "Appliance Configuration" menu.

Check Contents

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "A" for "Appliance Configuration Menu," and then press "Enter".

4. Press "3" for "NTP Configuration," and then press "Enter".

If there is no address or only a single address listed for "Currently configured ntp servers:", this is a finding.

If the "Currently configured ntp servers:" list is not the organizationally mandated list of geographically distributed time servers, this is a finding.

Vulnerability Number

V-254867

Documentable

False

Rule Version

TANS-OS-001105

Severity Override Guidance

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "A" for "Appliance Configuration Menu," and then press "Enter".

4. Press "3" for "NTP Configuration," and then press "Enter".

If there is no address or only a single address listed for "Currently configured ntp servers:", this is a finding.

If the "Currently configured ntp servers:" list is not the organizationally mandated list of geographically distributed time servers, this is a finding.

Check Content Reference

M

Target Key

5491