STIGQter STIGQter: STIG Summary:

Tanium 7.x Security Technical Implementation Guide

Version: 2

Release: 3 Benchmark Date: 02 Jul 2025

CheckedNameTitle
SV-253779r997220_ruleThe Tanium application must be configured to send audit records from multiple components within the system to a central location for review and analysis.
SV-253780r997221_ruleThe application must, at a minimum, offload interconnected systems in real time and offload standalone systems weekly.
SV-253781r1099925_ruleTanium Client processes must be excluded from On-Access scan.
SV-253782r997223_ruleThe Tanium application must be configured for LDAP user/group synchronization to map the authenticated identity to the individual user or group account for PKI-based authentication.
SV-253783r997224_ruleThe Tanium application must uniquely identify and authenticate nonorganizational users (or processes acting on behalf of nonorganizational users).
SV-253784r997225_ruleThe Tanium application must separate user functionality (including user interface services) from information system management functionality.
SV-253785r997226_ruleThe Tanium Server and Client applications must have logging enabled.
SV-253786r1067649_ruleThe Tanium application must restrict the ability of individuals to use information systems to launch organization-defined denial-of-service (DoS) attacks against other information systems.
SV-253787r1099927_ruleThe Tanium application must manage bandwidth throttles to limit the effects of information flooding types of denial-of-service (DoS) attacks.
SV-253788r997229_ruleThe Tanium application must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
SV-253789r997230_ruleThe Tanium application must reveal error messages only to the information system security officer (ISSO), information system security manager (ISSM), and system administrator (SA).
SV-253791r997231_ruleThe Tanium application must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-253792r997232_ruleThe Tanium application must offload audit records onto a different system or media than the system being audited.
SV-253793r997233_ruleThe Tanium application must provide an immediate warning to the system administrator and information system security officer (at a minimum) when allocated audit record storage volume reaches 75% of repository maximum audit record storage capacity.
SV-253794r1099929_ruleThe Tanium application must provide an immediate real-time alert to the system administrator and information system security officer, at a minimum, of all audit failure events requiring real-time alerts.
SV-253795r1015837_ruleThe Tanium application must prohibit user installation of software without explicit privileged status.
SV-253796r997235_ruleThe application must enforce access restrictions associated with changes to application configuration.
SV-253797r997236_ruleThe application must employ a deny-all, permit-by-exception (allowlist) policy to allow the execution of authorized software programs.
SV-253798r997237_ruleThe Tanium application must accept Personal Identity Verification (PIV) credentials.
SV-253799r997238_ruleThe Tanium application must electronically verify Personal Identity Verification (PIV) credentials.
SV-253800r1099931_ruleThe Tanium application must accept Personal Identity Verification (PIV) credentials from other federal agencies.
SV-253801r997240_ruleThe Tanium application must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).
SV-253802r997241_ruleTanium must alert the ISSO, ISSM, and other individuals designated by the local organization when the following Indicators of Compromise (IOCs) or potential compromise are detected: real-time intrusion detection; threats identified by authoritative sources (e.g., CTOs); and Category I, II, IV, and VII incidents in accordance with CJCSM 6510.01B.
SV-253803r1099932_ruleTanium Server processes must be excluded from On-Access scan.
SV-253804r1067652_ruleThe Tanium application must authenticate endpoint devices (servers) before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
SV-253805r960762_ruleThe Tanium endpoint must have the Tanium Server's pki.db in its installation.
SV-253806r997244_ruleAccess to Tanium logs on each endpoint must be restricted by permissions.
SV-253807r1067655_ruleThe Tanium cryptographic signing capabilities must be enabled on the Tanium Clients to safeguard the authenticity of communications sessions when answering requests from the Tanium Server.
SV-253808r1043177_ruleFirewall rules must be configured on the Tanium endpoints for client-to-server communications.
SV-253809r997246_ruleControl of the Tanium Client service must be restricted to SYSTEM access only for all managed clients.
SV-253810r997247_ruleThe ability to uninstall the Tanium Client service must be disabled on all managed clients.
SV-253811r997248_ruleThe permissions on the Tanium Client directory must be restricted to only the SYSTEM account on all managed clients.
SV-253812r1099933_ruleTanium Client directory and subsequent files must be excluded from On-Access scan.
SV-253813r1099934_ruleTanium endpoint files must be excluded from host-based intrusion prevention system (HIPS) intervention.
SV-253814r1099936_ruleThe Tanium application must retain the session lock until the user reestablishes access using established identification and authentication procedures.
SV-253815r1099938_ruleThe Tanium Application Server must be configured with a connector to sync to Microsoft Active Directory for account management functions.
SV-253816r1099940_ruleThe Tanium Application Server must be configured to only use LDAP for account management functions.
SV-253817r1099942_ruleTanium Computer Groups must be used to restrict console users from effecting changes to unauthorized computers.
SV-253818r997254_ruleDocumentation identifying Tanium console users, their respective User Groups, Computer Groups, and Roles must be maintained.
SV-253819r997255_ruleThe Tanium application must be configured to use Tanium User Groups in a manner consistent with the model outlined in the environment's system documentation.
SV-253820r997256_ruleDocumentation identifying Tanium console users and their respective Computer Group rights must be maintained.
SV-253821r1099944_ruleMultifactor authentication must be enabled on the Tanium Server for network access with privileged accounts.
SV-253822r1099945_ruleFirewall rules must be configured on the Tanium Server for Console-to-Server communications.
SV-253823r960843_ruleThe publicly accessible Tanium application must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the application.
SV-253824r997258_ruleThe Tanium application must alert the information system security officer and system administrator (at a minimum) in the event of an audit processing failure.
SV-253825r1015841_ruleTanium must notify system administrator and information system security officer (ISSO) when accounts are created.
SV-253826r1015842_ruleTanium must notify system administrators and the information system security officer (ISSO) when accounts are modified.
SV-253827r1015843_ruleTanium must notify the system administrator and information system security officer (ISSO) of account enabling actions.
SV-253828r1099947_ruleMultifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
SV-253829r1015845_ruleTanium must notify system administrators and the information system security officer (ISSO) for account disabling actions.
SV-253830r1015846_ruleTanium must notify system administrators and the information system security officer (ISSO) for account removal actions.
SV-253831r960939_ruleThe Tanium application must prohibit user installation, modification, or deletion of software without explicit privileged status.
SV-253832r1099949_ruleThe Tanium database(s) must be installed on a separate system.
SV-253833r997260_ruleThe Tanium application database must be dedicated to only the Tanium application.
SV-253834r1015847_ruleThe access to the Tanium SQL database must be restricted. Only the designated database administrator(s) can have elevated privileges to the Tanium SQL database.
SV-253835r1015848_ruleThe Tanium Server installer's account database permissions must be reduced to an appropriate level.
SV-253836r1099950_ruleFirewall rules must be configured on the Tanium Server for server-to-database communications.
SV-253837r1067658_ruleThe Tanium Application Server console must be configured to initiate a session lock after a 15-minute period of inactivity.
SV-253838r997263_ruleTanium Trusted Content providers must be documented.
SV-253839r997264_ruleContent providers must provide their public key to the Tanium administrator to import for validating signed content.
SV-253840r997265_ruleTanium public keys of content providers must be validated against documented trusted content providers.
SV-253841r1067661_ruleThe Tanium Action Approval feature must be enabled for two-person integrity when deploying actions to endpoints.
SV-253842r997266_ruleThe Tanium documentation identifying recognized and trusted indicator of compromise (IOC) streams must be maintained.
SV-253843r997267_ruleTanium Threat Response must be configured to receive IOC streams only from trusted sources.
SV-253844r997268_ruleThe Tanium applications must be configured to filter audit records for events of interest based on organization-defined criteria.
SV-253845r1067664_ruleThe Tanium cryptographic signing capabilities must be enabled on the Tanium Server.
SV-253846r1067667_ruleThe Tanium Server must be configured to allow only signed content to be imported.
SV-253847r997269_ruleAll installation files originally downloaded to the Tanium Server must be configured to download to a location other than the Tanium Server directory.
SV-253848r1099951_ruleFirewall rules must be configured on the Tanium Server for client-to-server communications.
SV-253849r1099952_ruleFirewall rules must be configured on the Tanium Zone Server for Client-to-Zone Server communications.
SV-253850r1043177_ruleThe Tanium Application Server must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM Category Assurance List (CAL) and vulnerability assessments.
SV-253851r997273_ruleThe Tanium Server certificates must have Extended Key Usage entries for the serverAuth object TLS Web Server Authentication and the clientAuth object TLS Web Client Authentication.
SV-253852r997274_ruleThe Tanium Server directory must be restricted with appropriate permissions.
SV-253853r997275_ruleThe Tanium Server http directory and subdirectories must be restricted with appropriate permissions.
SV-253854r997276_ruleThe permissions on the Tanium Server registry keys must be restricted to only the Tanium service account and the [Tanium Admins] group.
SV-253855r997277_ruleThe Tanium Server Logs and TDL_Logs directories must be restricted with appropriate permissions.
SV-253856r1099953_ruleFirewall rules must be configured on the Tanium module server to allow Server-to-Module Server communications from the Tanium Server.
SV-253857r1099954_ruleFirewall rules must be configured on the Tanium Server for Server-to-Module Server communications.
SV-253858r997280_ruleFirewall rules must be configured on the Tanium Server for Server-to-Zone Server communications.
SV-253859r997281_ruleThe SSLHonorCipherOrder must be configured to disable weak encryption algorithms on the Tanium Server.
SV-253860r997282_ruleThe Tanium Server certificate must be signed by a DoD certificate authority (CA).
SV-253861r1099955_ruleTanium Server directory and subsequent files must be excluded from On-Access scan.
SV-253862r997284_ruleThe SSLCipherSuite must be configured to disable weak encryption algorithms on the Tanium Server.
SV-253863r1067670_ruleThe Tanium "max_soap_sessions_total" setting must be explicitly enabled to limit the number of simultaneous sessions.
SV-253864r997286_ruleThe Tanium "max_soap_sessions_per_user" setting must be explicitly enabled to limit the number of simultaneous sessions.
SV-253865r997287_ruleThe Tanium documentation identifying recognized and trusted folders for Threat Response Local Directory Source must be maintained.
SV-253866r997288_ruleThe Tanium Threat Response Local Directory Source must be configured to restrict access to only authorized maintainers of threat intel.
SV-253867r997289_ruleThe Tanium documentation identifying recognized and trusted Security Content Automation Protocol (SCAP) sources must be maintained.
SV-253868r997290_ruleThe Tanium documentation identifying recognized and trusted Open Vulnerability and Assessment Language (OVAL) feeds must be maintained.
SV-253869r997291_ruleTanium Comply must be configured to receive Security Content Automation Protocol (SCAP) content only from trusted sources.
SV-253870r997292_ruleTanium Comply must be configured to receive Open Vulnerability and Assessment Language (OVAL) feeds only from trusted sources.
SV-253871r1099957_ruleThe Tanium application must limit the bandwidth used in communicating with endpoints to prevent a denial-of-service (DoS) condition at the server.
SV-253872r1082009_ruleTanium Server files must be excluded from host-based intrusion prevention intervention.
SV-253873r1043182_ruleThe Tanium application must set an inactive timeout for sessions.
SV-253874r997296_ruleThe Tanium application service must be protected from being stopped by a nonprivileged user.
SV-253875r997297_ruleThe Tanium Application, SQL, and Module servers must all be configured to communicate using TLS 1.2 Strict Only.
SV-253876r997298_ruleThe SchUseStrongCrypto registry value must be set.
SV-253877r997299_ruleThe SSLCipherSuite registry value must be set.