| Checked | Name | Title |
|---|
| ☐ | SV-253779r997220_rule | The Tanium application must be configured to send audit records from multiple components within the system to a central location for review and analysis. |
| ☐ | SV-253780r997221_rule | The application must, at a minimum, offload interconnected systems in real time and offload standalone systems weekly. |
| ☐ | SV-253781r1099925_rule | Tanium Client processes must be excluded from On-Access scan. |
| ☐ | SV-253782r997223_rule | The Tanium application must be configured for LDAP user/group synchronization to map the authenticated identity to the individual user or group account for PKI-based authentication. |
| ☐ | SV-253783r997224_rule | The Tanium application must uniquely identify and authenticate nonorganizational users (or processes acting on behalf of nonorganizational users). |
| ☐ | SV-253784r997225_rule | The Tanium application must separate user functionality (including user interface services) from information system management functionality. |
| ☐ | SV-253785r997226_rule | The Tanium Server and Client applications must have logging enabled. |
| ☐ | SV-253786r1067649_rule | The Tanium application must restrict the ability of individuals to use information systems to launch organization-defined denial-of-service (DoS) attacks against other information systems. |
| ☐ | SV-253787r1099927_rule | The Tanium application must manage bandwidth throttles to limit the effects of information flooding types of denial-of-service (DoS) attacks. |
| ☐ | SV-253788r997229_rule | The Tanium application must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries. |
| ☐ | SV-253789r997230_rule | The Tanium application must reveal error messages only to the information system security officer (ISSO), information system security manager (ISSM), and system administrator (SA). |
| ☐ | SV-253791r997231_rule | The Tanium application must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements. |
| ☐ | SV-253792r997232_rule | The Tanium application must offload audit records onto a different system or media than the system being audited. |
| ☐ | SV-253793r997233_rule | The Tanium application must provide an immediate warning to the system administrator and information system security officer (at a minimum) when allocated audit record storage volume reaches 75% of repository maximum audit record storage capacity. |
| ☐ | SV-253794r1099929_rule | The Tanium application must provide an immediate real-time alert to the system administrator and information system security officer, at a minimum, of all audit failure events requiring real-time alerts. |
| ☐ | SV-253795r1015837_rule | The Tanium application must prohibit user installation of software without explicit privileged status. |
| ☐ | SV-253796r997235_rule | The application must enforce access restrictions associated with changes to application configuration. |
| ☐ | SV-253797r997236_rule | The application must employ a deny-all, permit-by-exception (allowlist) policy to allow the execution of authorized software programs. |
| ☐ | SV-253798r997237_rule | The Tanium application must accept Personal Identity Verification (PIV) credentials. |
| ☐ | SV-253799r997238_rule | The Tanium application must electronically verify Personal Identity Verification (PIV) credentials. |
| ☐ | SV-253800r1099931_rule | The Tanium application must accept Personal Identity Verification (PIV) credentials from other federal agencies. |
| ☐ | SV-253801r997240_rule | The Tanium application must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs). |
| ☐ | SV-253802r997241_rule | Tanium must alert the ISSO, ISSM, and other individuals designated by the local organization when the following Indicators of Compromise (IOCs) or potential compromise are detected: real-time intrusion detection; threats identified by authoritative sources (e.g., CTOs); and Category I, II, IV, and VII incidents in accordance with CJCSM 6510.01B. |
| ☐ | SV-253803r1099932_rule | Tanium Server processes must be excluded from On-Access scan. |
| ☐ | SV-253804r1067652_rule | The Tanium application must authenticate endpoint devices (servers) before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based. |
| ☐ | SV-253805r960762_rule | The Tanium endpoint must have the Tanium Server's pki.db in its installation. |
| ☐ | SV-253806r997244_rule | Access to Tanium logs on each endpoint must be restricted by permissions. |
| ☐ | SV-253807r1067655_rule | The Tanium cryptographic signing capabilities must be enabled on the Tanium Clients to safeguard the authenticity of communications sessions when answering requests from the Tanium Server. |
| ☐ | SV-253808r1043177_rule | Firewall rules must be configured on the Tanium endpoints for client-to-server communications. |
| ☐ | SV-253809r997246_rule | Control of the Tanium Client service must be restricted to SYSTEM access only for all managed clients. |
| ☐ | SV-253810r997247_rule | The ability to uninstall the Tanium Client service must be disabled on all managed clients. |
| ☐ | SV-253811r997248_rule | The permissions on the Tanium Client directory must be restricted to only the SYSTEM account on all managed clients. |
| ☐ | SV-253812r1099933_rule | Tanium Client directory and subsequent files must be excluded from On-Access scan. |
| ☐ | SV-253813r1099934_rule | Tanium endpoint files must be excluded from host-based intrusion prevention system (HIPS) intervention. |
| ☐ | SV-253814r1099936_rule | The Tanium application must retain the session lock until the user reestablishes access using established identification and authentication procedures. |
| ☐ | SV-253815r1099938_rule | The Tanium Application Server must be configured with a connector to sync to Microsoft Active Directory for account management functions. |
| ☐ | SV-253816r1099940_rule | The Tanium Application Server must be configured to only use LDAP for account management functions. |
| ☐ | SV-253817r1099942_rule | Tanium Computer Groups must be used to restrict console users from effecting changes to unauthorized computers. |
| ☐ | SV-253818r997254_rule | Documentation identifying Tanium console users, their respective User Groups, Computer Groups, and Roles must be maintained. |
| ☐ | SV-253819r997255_rule | The Tanium application must be configured to use Tanium User Groups in a manner consistent with the model outlined in the environment's system documentation. |
| ☐ | SV-253820r997256_rule | Documentation identifying Tanium console users and their respective Computer Group rights must be maintained. |
| ☐ | SV-253821r1099944_rule | Multifactor authentication must be enabled on the Tanium Server for network access with privileged accounts. |
| ☐ | SV-253822r1099945_rule | Firewall rules must be configured on the Tanium Server for Console-to-Server communications. |
| ☐ | SV-253823r960843_rule | The publicly accessible Tanium application must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the application. |
| ☐ | SV-253824r997258_rule | The Tanium application must alert the information system security officer and system administrator (at a minimum) in the event of an audit processing failure. |
| ☐ | SV-253825r1015841_rule | Tanium must notify system administrator and information system security officer (ISSO) when accounts are created. |
| ☐ | SV-253826r1015842_rule | Tanium must notify system administrators and the information system security officer (ISSO) when accounts are modified. |
| ☐ | SV-253827r1015843_rule | Tanium must notify the system administrator and information system security officer (ISSO) of account enabling actions. |
| ☐ | SV-253828r1099947_rule | Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts. |
| ☐ | SV-253829r1015845_rule | Tanium must notify system administrators and the information system security officer (ISSO) for account disabling actions. |
| ☐ | SV-253830r1015846_rule | Tanium must notify system administrators and the information system security officer (ISSO) for account removal actions. |
| ☐ | SV-253831r960939_rule | The Tanium application must prohibit user installation, modification, or deletion of software without explicit privileged status. |
| ☐ | SV-253832r1099949_rule | The Tanium database(s) must be installed on a separate system. |
| ☐ | SV-253833r997260_rule | The Tanium application database must be dedicated to only the Tanium application. |
| ☐ | SV-253834r1015847_rule | The access to the Tanium SQL database must be restricted. Only the designated database administrator(s) can have elevated privileges to the Tanium SQL database. |
| ☐ | SV-253835r1015848_rule | The Tanium Server installer's account database permissions must be reduced to an appropriate level. |
| ☐ | SV-253836r1099950_rule | Firewall rules must be configured on the Tanium Server for server-to-database communications. |
| ☐ | SV-253837r1067658_rule | The Tanium Application Server console must be configured to initiate a session lock after a 15-minute period of inactivity. |
| ☐ | SV-253838r997263_rule | Tanium Trusted Content providers must be documented. |
| ☐ | SV-253839r997264_rule | Content providers must provide their public key to the Tanium administrator to import for validating signed content. |
| ☐ | SV-253840r997265_rule | Tanium public keys of content providers must be validated against documented trusted content providers. |
| ☐ | SV-253841r1067661_rule | The Tanium Action Approval feature must be enabled for two-person integrity when deploying actions to endpoints. |
| ☐ | SV-253842r997266_rule | The Tanium documentation identifying recognized and trusted indicator of compromise (IOC) streams must be maintained. |
| ☐ | SV-253843r997267_rule | Tanium Threat Response must be configured to receive IOC streams only from trusted sources. |
| ☐ | SV-253844r997268_rule | The Tanium applications must be configured to filter audit records for events of interest based on organization-defined criteria. |
| ☐ | SV-253845r1067664_rule | The Tanium cryptographic signing capabilities must be enabled on the Tanium Server. |
| ☐ | SV-253846r1067667_rule | The Tanium Server must be configured to allow only signed content to be imported. |
| ☐ | SV-253847r997269_rule | All installation files originally downloaded to the Tanium Server must be configured to download to a location other than the Tanium Server directory. |
| ☐ | SV-253848r1099951_rule | Firewall rules must be configured on the Tanium Server for client-to-server communications. |
| ☐ | SV-253849r1099952_rule | Firewall rules must be configured on the Tanium Zone Server for Client-to-Zone Server communications. |
| ☐ | SV-253850r1043177_rule | The Tanium Application Server must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM Category Assurance List (CAL) and vulnerability assessments. |
| ☐ | SV-253851r997273_rule | The Tanium Server certificates must have Extended Key Usage entries for the serverAuth object TLS Web Server Authentication and the clientAuth object TLS Web Client Authentication. |
| ☐ | SV-253852r997274_rule | The Tanium Server directory must be restricted with appropriate permissions. |
| ☐ | SV-253853r997275_rule | The Tanium Server http directory and subdirectories must be restricted with appropriate permissions. |
| ☐ | SV-253854r997276_rule | The permissions on the Tanium Server registry keys must be restricted to only the Tanium service account and the [Tanium Admins] group. |
| ☐ | SV-253855r997277_rule | The Tanium Server Logs and TDL_Logs directories must be restricted with appropriate permissions. |
| ☐ | SV-253856r1099953_rule | Firewall rules must be configured on the Tanium module server to allow Server-to-Module Server communications from the Tanium Server. |
| ☐ | SV-253857r1099954_rule | Firewall rules must be configured on the Tanium Server for Server-to-Module Server communications. |
| ☐ | SV-253858r997280_rule | Firewall rules must be configured on the Tanium Server for Server-to-Zone Server communications. |
| ☐ | SV-253859r997281_rule | The SSLHonorCipherOrder must be configured to disable weak encryption algorithms on the Tanium Server. |
| ☐ | SV-253860r997282_rule | The Tanium Server certificate must be signed by a DoD certificate authority (CA). |
| ☐ | SV-253861r1099955_rule | Tanium Server directory and subsequent files must be excluded from On-Access scan. |
| ☐ | SV-253862r997284_rule | The SSLCipherSuite must be configured to disable weak encryption algorithms on the Tanium Server. |
| ☐ | SV-253863r1067670_rule | The Tanium "max_soap_sessions_total" setting must be explicitly enabled to limit the number of simultaneous sessions. |
| ☐ | SV-253864r997286_rule | The Tanium "max_soap_sessions_per_user" setting must be explicitly enabled to limit the number of simultaneous sessions. |
| ☐ | SV-253865r997287_rule | The Tanium documentation identifying recognized and trusted folders for Threat Response Local Directory Source must be maintained. |
| ☐ | SV-253866r997288_rule | The Tanium Threat Response Local Directory Source must be configured to restrict access to only authorized maintainers of threat intel. |
| ☐ | SV-253867r997289_rule | The Tanium documentation identifying recognized and trusted Security Content Automation Protocol (SCAP) sources must be maintained. |
| ☐ | SV-253868r997290_rule | The Tanium documentation identifying recognized and trusted Open Vulnerability and Assessment Language (OVAL) feeds must be maintained. |
| ☐ | SV-253869r997291_rule | Tanium Comply must be configured to receive Security Content Automation Protocol (SCAP) content only from trusted sources. |
| ☐ | SV-253870r997292_rule | Tanium Comply must be configured to receive Open Vulnerability and Assessment Language (OVAL) feeds only from trusted sources. |
| ☐ | SV-253871r1099957_rule | The Tanium application must limit the bandwidth used in communicating with endpoints to prevent a denial-of-service (DoS) condition at the server. |
| ☐ | SV-253872r1082009_rule | Tanium Server files must be excluded from host-based intrusion prevention intervention. |
| ☐ | SV-253873r1043182_rule | The Tanium application must set an inactive timeout for sessions. |
| ☐ | SV-253874r997296_rule | The Tanium application service must be protected from being stopped by a nonprivileged user. |
| ☐ | SV-253875r997297_rule | The Tanium Application, SQL, and Module servers must all be configured to communicate using TLS 1.2 Strict Only. |
| ☐ | SV-253876r997298_rule | The SchUseStrongCrypto registry value must be set. |
| ☐ | SV-253877r997299_rule | The SSLCipherSuite registry value must be set. |