STIGQter STIGQter: STIG Summary: Tanium 7.3 Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The Tanium Application Server must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.

DISA Rule

SV-234091r612749_rule

Vulnerability Number

V-234091

Group Title

SRG-APP-000142

Rule Version

TANS-SV-000019

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Submit a formal request to have the Tanium communication ports evaluated and added to the PPSM CAL.

Check Contents

Review the PPSM CAL to ensure Tanium has been registered with all of the TCP ports required for functionality to include (but not limited to) TCP 17472, 17477, 17440, 17441, 443, and 1433.

If any TCP ports are being used on the Tanium Server that have been deemed as restricted by the PPSM CAL, this is a finding.

Vulnerability Number

V-234091

Documentable

False

Rule Version

TANS-SV-000019

Severity Override Guidance

Review the PPSM CAL to ensure Tanium has been registered with all of the TCP ports required for functionality to include (but not limited to) TCP 17472, 17477, 17440, 17441, 443, and 1433.

If any TCP ports are being used on the Tanium Server that have been deemed as restricted by the PPSM CAL, this is a finding.

Check Content Reference

M

Target Key

5259

Comments