STIGQter STIGQter: STIG Summary: Tanium 7.x Application on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

The Tanium application must enforce a 60-day maximum password lifetime restriction.

DISA Rule

SV-254913r1043190_rule

Vulnerability Number

V-254913

Group Title

SRG-APP-000174

Rule Version

TANS-AP-000475

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Console Users:

Per guidance, Enterprise Console users are inherited via LDAP synchronization as such passwords are not managed or enforced at the Tanium application level.

Local TanOS account:

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Enter "" for "User Administration Menu," and then press "Enter".

4. Enter "L" for "Local Tanium User Management," and then press "Enter".

5. Enter "B" for "Security Policy Local Authentication Service," and then press "Enter".

6. Type "yes," and then press "Enter".

7. Input the following settings, pressing "Enter" after every value:
a) Minimum Password Lifetime - 1
b) Maximum Password Lifetime - 60
c) Minimum Password Length - 15
d) Minimum Password History - 5
e) Password Lockout - TRUE
f) Maximum Password Attempts - 3

8. Type "yes" to accept the new password policy.

Check Contents

Console Users:

Per guidance, Enterprise Console users are inherited via LDAP synchronization as such passwords are not managed or enforced at the Tanium application level.

Local TanOS account:

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Enter "C" for "User Administration Menu," and then press "Enter".

4. Enter "L" for " Local Tanium User Management," and then press "Enter".

5. Enter "B" for " Security Policy Local Authentication Service," and then press "Enter".

If the value of "Password Maximum Age (days):" is greater than "60", this is a finding.

Vulnerability Number

V-254913

Documentable

False

Rule Version

TANS-AP-000475

Severity Override Guidance

Console Users:

Per guidance, Enterprise Console users are inherited via LDAP synchronization as such passwords are not managed or enforced at the Tanium application level.

Local TanOS account:

1. Access the Tanium Server interactively.

2. Log on to the TanOS server with the tanadmin role.

3. Enter "C" for "User Administration Menu," and then press "Enter".

4. Enter "L" for " Local Tanium User Management," and then press "Enter".

5. Enter "B" for " Security Policy Local Authentication Service," and then press "Enter".

If the value of "Password Maximum Age (days):" is greater than "60", this is a finding.

Check Content Reference

M

Target Key

5492