STIGQter STIGQter: STIG Summary: Tanium 7.3 Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The Tanium application must be configured in a High-Availability (HA) setup to ensure minimal loss of data and minimal disruption to mission processes in the event of a system failure.

DISA Rule

SV-234120r612749_rule

Vulnerability Number

V-234120

Group Title

SRG-APP-000226

Rule Version

TANS-SV-000054

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the system is not considered mission critical, this is Not Applicable.

Work with the Tanium System Administrator to configure Tanium in a HA Active-Active setup based on the process outlined in the Tanium documentation found at:

https://docs.tanium.com/platform_install/platform_install/installing_an_ha_active_active_cluster.html.

Check Contents

If the system is not considered mission critical, this is Not Applicable.

Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI).

Log on with CAC.

Click on the navigation button (hamburger menu) on the top left of the console.

Click on "Packages".

Browse to the package called "Distribute Tanium Standard Utilities".

Select it.

Press "Status".

Observe the text underneath a package file indicating the file cache status.

If the cache status represents only one Tanium Server, this is a finding.

Vulnerability Number

V-234120

Documentable

False

Rule Version

TANS-SV-000054

Severity Override Guidance

If the system is not considered mission critical, this is Not Applicable.

Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI).

Log on with CAC.

Click on the navigation button (hamburger menu) on the top left of the console.

Click on "Packages".

Browse to the package called "Distribute Tanium Standard Utilities".

Select it.

Press "Status".

Observe the text underneath a package file indicating the file cache status.

If the cache status represents only one Tanium Server, this is a finding.

Check Content Reference

M

Target Key

5259

Comments