Check: TANS-SV-000007
Tanium 7.x STIG:
TANS-SV-000007
(in versions v2 r1 through v1 r1)
Title
The Tanium documentation identifying recognized and trusted indicator of compromise (IOC) streams must be maintained. (Cat II impact)
Discussion
Using trusted and recognized IOC sources may detect compromise and prevent systems from becoming compromised. An IOC stream is a series or stream of IOCs that are imported from a vendor based on a subscription service. An IOC stream can be downloaded manually or on a scheduled basis. The items in an IOC stream can be manipulated separately after they are imported.
Check Content
Consult with the Tanium system administrator to determine if the Threat Response module is being used. If it is not, this is not applicable. Review the documented list of IOC trusted stream sources. If the site uses an external source for IOCs and the IOC trusted stream source is not documented, this is a finding.
Fix Text
Prepare and maintain documentation identifying the Threat Response trusted stream sources.
Additional Identifiers
Rule ID: SV-253842r997266_rule
Vulnerability ID: V-253842
Group Title: SRG-APP-000039
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001414 |
Enforce approved authorizations for controlling the flow of information between connected systems based on organization-defined information flow control policies. |
Controls
Number | Title |
---|---|
AC-4 |
Information Flow Enforcement |