Skip to content

Access to Tanium logs on each endpoint must be restricted by permissions.

An XCCDF Rule

Description

<VulnDiscussion>For the Tanium Client software to run without impact from external negligent or malicious changes, the permissions on the Tanium log files and their directory must be restricted. Tanium is deployed with a Client Hardening Solution. This solution, when applied, will ensure directory permissions are in place.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-93285r1_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Using a web browser on a system that has connectivity to Tanium, access the Tanium web UI and log on with CAC.

On the Dashboard, select "Client Service Hardening".

Select the "Set Client Directory Permissions".