STIGQter STIGQter: STIG Summary: Tanium 7.0 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 27 July 2018:

Any Tanium configured EMAIL RESULTS connectors must be configured to enable TLS/SSL to encrypt communications.

DISA Rule

SV-93423r1_rule

Vulnerability Number

V-78717

Group Title

SRG-APP-000442

Rule Version

TANS-SV-000037

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Using a web browser on a system that has connectivity to Tanium, access the Tanium web UI and log on with CAC.

Click on the navigation button (hamburger menu) on the top left of the console.

Click on "Connect".

Click on "Email" on the Destinations column.

Select each "Email" connector that is configured with "Enable TLS" set to "false".

Click the "Edit" button at the top right of the screen.

Place a check in the "Enable TLS" check box.

Click on "Save Changes".

Check Contents

Using a web browser on a system that has connectivity to Tanium, access the Tanium web user interface (UI) and log on with CAC.

Click on the navigation button (hamburger menu) on the top left of the console.

Click on "Connect".

If no "Email" connectors are configured under "Destinations", this is Not Applicable.

For each "Email" connector, select the connector to reveal its properties.

Validate the "Enable TLS" is set to "true".

If any configured "Email" connectors are configured for "Enable TLS" set to "false", this is a finding.

Vulnerability Number

V-78717

Documentable

False

Rule Version

TANS-SV-000037

Severity Override Guidance

Using a web browser on a system that has connectivity to Tanium, access the Tanium web user interface (UI) and log on with CAC.

Click on the navigation button (hamburger menu) on the top left of the console.

Click on "Connect".

If no "Email" connectors are configured under "Destinations", this is Not Applicable.

For each "Email" connector, select the connector to reveal its properties.

Validate the "Enable TLS" is set to "true".

If any configured "Email" connectors are configured for "Enable TLS" set to "false", this is a finding.

Check Content Reference

M

Target Key

3215

Comments