STIGQter STIGQter: STIG Summary: Tanium 7.0 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 27 July 2018:

The Tanium documentation identifying recognized and trusted OVAL feeds must be maintained.

DISA Rule

SV-93443r1_rule

Vulnerability Number

V-78737

Group Title

SRG-APP-000039

Rule Version

TANS-SV-000051

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the site does not have "Tanium Comply" module, or does not use "Tanium Comply" for passive vulnerability scanning, this finding is "Not Applicable".

Prepare and maintain documentation identifying the source of OVAL feeds that will be used by "Tanium Comply" module.

Check Contents

Consult with the Tanium System Administrator to review the documented list of trusted OVAL feeds.

If the site does not have "Tanium Comply" module, or does not use "Tanium Comply" for passive vulnerability scanning, this finding is "Not Applicable".

Otherwise, if the site does use "Tanium Comply" and the source for OVAL content is not documented, this is a finding.

Vulnerability Number

V-78737

Documentable

False

Rule Version

TANS-SV-000051

Severity Override Guidance

Consult with the Tanium System Administrator to review the documented list of trusted OVAL feeds.

If the site does not have "Tanium Comply" module, or does not use "Tanium Comply" for passive vulnerability scanning, this finding is "Not Applicable".

Otherwise, if the site does use "Tanium Comply" and the source for OVAL content is not documented, this is a finding.

Check Content Reference

M

Target Key

3215

Comments