STIGQter STIGQter: STIG Summary: Tanium 7.0 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 27 July 2018:

The Tanium Server installers account SQL database permissions must be reduced from sysadmin to db_owner.

DISA Rule

SV-93357r1_rule

Vulnerability Number

V-78651

Group Title

SRG-APP-000381

Rule Version

TANS-DB-000004

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Access the Tanium SQL server interactively.

Log on with an account with administrative privileges to the server.

Open SQL Server Management Studio and connect to Tanium instance of SQL Server.

In the left pane, click "Databases".
Select the Tanium database.
Click "Security".
Click "Users".

In the "Users" pane, right-click the Tanium Server service user account, and on the shortcut menu, click "Properties".

Under Database role membership, change role from sysadmin to db_owner.

Click "OK".

Check Contents

Access the Tanium SQL server interactively.

Log on with an account with administrative privileges to the server.

Open SQL Server Management Studio and connect to a Tanium instance of SQL Server.

In the left pane, click "Databases".
Select the Tanium database.
Click "Security".
Click "Users".

In the "Users" pane, review the role assigned to the Tanium Server service user account.

If the role assigned to the Tanium Server service account is not db_owner, this is a finding.

Vulnerability Number

V-78651

Documentable

False

Rule Version

TANS-DB-000004

Severity Override Guidance

Access the Tanium SQL server interactively.

Log on with an account with administrative privileges to the server.

Open SQL Server Management Studio and connect to a Tanium instance of SQL Server.

In the left pane, click "Databases".
Select the Tanium database.
Click "Security".
Click "Users".

In the "Users" pane, review the role assigned to the Tanium Server service user account.

If the role assigned to the Tanium Server service account is not db_owner, this is a finding.

Check Content Reference

M

Target Key

3215

Comments