SV-234095r612749_rule
V-234095
SRG-APP-000328
TANS-SV-000024
CAT II
10
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Open an Explorer window.
Navigate to Program Files >> Tanium.
Right-click on the "Tanium Server" folder.
Select "Properties".
Select the "Security" tab.
Click on the "Advanced" button.
Disable folder inheritance.
Change the owner of the directory to the service account [Tanium service account].
Remove User permissions.
Give [Tanium service account] full permissions.
Give [Tanium Admins] group full permissions.
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Open an Explorer window.
Navigate to Program Files >> Tanium.
Right-click on the "Tanium Server" folder.
Select "Properties".
Select the "Security" tab.
Click on the "Advanced" button.
Validate the owner of the "Tanium Server" folder is the service account [Tanium service account].
Validate the [Tanium service account] has full permissions to the "Tanium Server" folder.
Validate the [Tanium Admins] group has full permissions to the "Tanium Server" folder.
Validate Users have no permissions to the "Tanium Server" folder.
If any accounts other than the [Tanium service account] and the [Tanium Admins] group have any permission to the "Tanium Server" folder, this is a finding.
If the [Tanium service account] is not the owner of the "Tanium Server" folder, this is a finding.
V-234095
False
TANS-SV-000024
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Open an Explorer window.
Navigate to Program Files >> Tanium.
Right-click on the "Tanium Server" folder.
Select "Properties".
Select the "Security" tab.
Click on the "Advanced" button.
Validate the owner of the "Tanium Server" folder is the service account [Tanium service account].
Validate the [Tanium service account] has full permissions to the "Tanium Server" folder.
Validate the [Tanium Admins] group has full permissions to the "Tanium Server" folder.
Validate Users have no permissions to the "Tanium Server" folder.
If any accounts other than the [Tanium service account] and the [Tanium Admins] group have any permission to the "Tanium Server" folder, this is a finding.
If the [Tanium service account] is not the owner of the "Tanium Server" folder, this is a finding.
M
5259