STIGQter STIGQter: STIG Summary: Tanium 7.x Application on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

Tanium must enforce 24 hours/one day as the minimum password lifetime.

DISA Rule

SV-254912r1015865_rule

Vulnerability Number

V-254912

Group Title

SRG-APP-000173

Rule Version

TANS-AP-000470

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Console Users:

Per guidance, Enterprise Console users are inherited via LDAP synchronization as such passwords are not managed or enforced at the Tanium application level.

Local TanOS account:

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "C" for "User Administration Menu," and then press "Enter".

4. Press "L" for "Local Tanium User Management," and then press "Enter".

5. Press "B" for "Security Policy Local Authentication Service," and then press "Enter".

6. Type "yes" and press "Enter".

7. Input the following settings, pressing "Enter" after every value:
a) Minimum Password Lifetime - 1
b) Maximum Password Lifetime - 60
c) Minimum Password Length - 15
d) Minimum Password History - 5
e) Password Lockout - TRUE
f) Maximum Password Attempts - 3

8. Type "yes" to accept the new password policy.

Check Contents

Console Users:

Per guidance, Enterprise Console users are inherited via LDAP synchronization as such passwords are not managed or enforced at the Tanium application level.

Local TanOS account:

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "C" for "User Administration Menu," and then press "Enter".

4. Press "L" for " Local Tanium User Management," and then press "Enter".

5. Press "B" for " Security Policy Local Authentication Service," and then press "Enter".

If the value of "Password Minimum Age (days):" is greater than "1", this is a finding.

Vulnerability Number

V-254912

Documentable

False

Rule Version

TANS-AP-000470

Severity Override Guidance

Console Users:

Per guidance, Enterprise Console users are inherited via LDAP synchronization as such passwords are not managed or enforced at the Tanium application level.

Local TanOS account:

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Press "C" for "User Administration Menu," and then press "Enter".

4. Press "L" for " Local Tanium User Management," and then press "Enter".

5. Press "B" for " Security Policy Local Authentication Service," and then press "Enter".

If the value of "Password Minimum Age (days):" is greater than "1", this is a finding.

Check Content Reference

M

Target Key

5492