SV-254901r960933_rule
V-254901
SRG-APP-000119
TANS-AP-000295
CAT II
10
1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.
2. Ask the question "Get Tanium Client Directory Permissions from all machines".
Tanium will parse the script and return a row for "Restricted" and a row for "Not Restricted", with their respective client counts.
3. Click the "Not Restricted" row.
4. Select "Deploy Action".
In the "Deploy Action" dialog box, the package "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory" will be selected.
The clients, which have their Tanium Client directory "Not Restricted" will be displayed in the bottom window.
5. Choose a schedule to deploy the hardening.
6. Under "Targeting Criteria," in the Action Group, select "All Computers" from the drop-down.
7. Click "Deploy Action".
8. Verify settings.
9. Click "Show Client Status Details".
1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.
2. Click "Administration" on the top navigation banner.
3. Under Actions, select "Scheduled Actions".
4. Look for a scheduled action titled "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory".
If a scheduled action titled "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory" does not exist, or there is a Scheduled Action contradicting the "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory" scheduled action, this is a finding.
If the scheduled action exists, select it and if it is not approved (the "Approve" button at the top of the section will be displayed if not approved), this is a finding.
V-254901
False
TANS-AP-000295
1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.
2. Click "Administration" on the top navigation banner.
3. Under Actions, select "Scheduled Actions".
4. Look for a scheduled action titled "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory".
If a scheduled action titled "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory" does not exist, or there is a Scheduled Action contradicting the "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory" scheduled action, this is a finding.
If the scheduled action exists, select it and if it is not approved (the "Approve" button at the top of the section will be displayed if not approved), this is a finding.
M
5492