STIGQter STIGQter: STIG Summary: Tanium 7.x Application on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

Access to Tanium logs on each endpoint must be restricted by permissions.

DISA Rule

SV-254901r960933_rule

Vulnerability Number

V-254901

Group Title

SRG-APP-000119

Rule Version

TANS-AP-000295

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Ask the question "Get Tanium Client Directory Permissions from all machines".

Tanium will parse the script and return a row for "Restricted" and a row for "Not Restricted", with their respective client counts.

3. Click the "Not Restricted" row.

4. Select "Deploy Action".

In the "Deploy Action" dialog box, the package "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory" will be selected.

The clients, which have their Tanium Client directory "Not Restricted" will be displayed in the bottom window.

5. Choose a schedule to deploy the hardening.

6. Under "Targeting Criteria," in the Action Group, select "All Computers" from the drop-down.

7. Click "Deploy Action".

8. Verify settings.

9. Click "Show Client Status Details".

Check Contents

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Administration" on the top navigation banner.

3. Under Actions, select "Scheduled Actions".

4. Look for a scheduled action titled "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory".

If a scheduled action titled "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory" does not exist, or there is a Scheduled Action contradicting the "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory" scheduled action, this is a finding.

If the scheduled action exists, select it and if it is not approved (the "Approve" button at the top of the section will be displayed if not approved), this is a finding.

Vulnerability Number

V-254901

Documentable

False

Rule Version

TANS-AP-000295

Severity Override Guidance

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Administration" on the top navigation banner.

3. Under Actions, select "Scheduled Actions".

4. Look for a scheduled action titled "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory".

If a scheduled action titled "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory" does not exist, or there is a Scheduled Action contradicting the "Client Service Hardening - Set SYSTEM only permissions on Tanium Client directory" scheduled action, this is a finding.

If the scheduled action exists, select it and if it is not approved (the "Approve" button at the top of the section will be displayed if not approved), this is a finding.

Check Content Reference

M

Target Key

5492