SV-234097r612749_rule
V-234097
SRG-APP-000328
TANS-SV-000026
CAT II
10
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Run regedit as Administrator.
Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Right-click on "Tanium Server".
Select "Properties".
Click on the "Security" tab.
Click on the "Advanced" button.
Provide the [Tanium service account] with full permissions.
Provide the [Tanium Admins] group with full permissions.
Reduce permissions for any other accounts with full permissions.
Remove permissions for User accounts.
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Run regedit as Administrator.
Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Right-click on "Tanium Server".
Select "Permissions".
Click on the "Security" tab.
Click on the "Advanced" button.
Validate the [Tanium service account] has full permissions.
Validate the [Tanium Admins] group has full permissions.
Validate the SYSTEM account has full permissions.
Validate the User accounts do not have any permissions.
If any other account has full permissions and/or the User account has any permissions, this is a finding.
V-234097
False
TANS-SV-000026
Access the Tanium Server interactively.
Log on to the server with an account that has administrative privileges.
Run regedit as Administrator.
Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> Wow6432Node >> Tanium >> Tanium Server.
Right-click on "Tanium Server".
Select "Permissions".
Click on the "Security" tab.
Click on the "Advanced" button.
Validate the [Tanium service account] has full permissions.
Validate the [Tanium Admins] group has full permissions.
Validate the SYSTEM account has full permissions.
Validate the User accounts do not have any permissions.
If any other account has full permissions and/or the User account has any permissions, this is a finding.
M
5259