SV-254931r961317_rule
V-254931
SRG-APP-000328
TANS-AP-000805
CAT II
10
1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Interact".
4. In the "Categories" section, select "Client Service Hardening".
5. In "Dashboard" section, select "Hide From Add-Remove Program".
6. The results will show a "Count" of clients matching the "Tanium Client Visible in Add-Remove Programs" query.
7. Select the result line.
8. Choose "Deploy Action".
9. The "Deploy Action" dialog box will display "Client Service Hardening - Hide Client from Add-Remove Programs" as the package. The computer names comprising the "count" of noncompliant systems will be displayed in the bottom.
10. Deployment Package drop-down select "Client Service Hardening - Hide Client from Add-Remove Programs".
11. Configure the schedule to repeat at least every hour for the requested action.
12. Under "Targeting Criteria", in the "Action Group," select "All Computers" from the drop-down.
13. Click "Show preview to continue". Noncompliant systems will be displayed in the bottom.
14. Click "Deploy Action".
15. Verify settings.
16. Click "Show Client Status Details".
1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.
2. Click "Administration" on the top navigation banner.
3. Under Actions, select "Scheduled Actions".
4. Look for a scheduled action titled "Client Service Hardening - Hide Client from Add-Remove Programs".
5. If a scheduled action titled "Client Service Hardening - Hide Client from Add-Remove Programs" does not exist, this is a finding.
If the scheduled action exists, select it and if it is not approved (the "Approve" button at the top of the section will be displayed if not approved), this is a finding.
If the scheduled action exists and has been approved but does not disable the visibility of the client in Add-Remove Programs, this is a finding.
If the action is not configured to repeat at least every hour, this is a finding.
If the scheduled action is not targeted at an "All Computers" Action Group, this is a finding.
V-254931
False
TANS-AP-000805
1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.
2. Click "Administration" on the top navigation banner.
3. Under Actions, select "Scheduled Actions".
4. Look for a scheduled action titled "Client Service Hardening - Hide Client from Add-Remove Programs".
5. If a scheduled action titled "Client Service Hardening - Hide Client from Add-Remove Programs" does not exist, this is a finding.
If the scheduled action exists, select it and if it is not approved (the "Approve" button at the top of the section will be displayed if not approved), this is a finding.
If the scheduled action exists and has been approved but does not disable the visibility of the client in Add-Remove Programs, this is a finding.
If the action is not configured to repeat at least every hour, this is a finding.
If the scheduled action is not targeted at an "All Computers" Action Group, this is a finding.
M
5492