V-253820
SV-253820r997256_rule
CAT II
Documentation identifying Tanium console users and their respective Computer Group rights must be maintained.
From: Tanium 7.x Security Technical Implementation Guide (V2R3)
Description
<VulnDiscussion>System access should be reviewed periodically to verify all Tanium users are assigned the appropriate computer groups, with the least privileged access possible to perform assigned tasks. Users who have been removed from the documentation should no longer be configured as a Tanium Console User.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
Check Procedure
Consult with the Tanium system administrator to review the documented list of Tanium users and their respective, approved Computer Group rights.
If the documented list does not have the Tanium users and their respective, approved Computer Group rights documented, this is a finding.
Fix Text
Prepare and maintain documentation identifying the Tanium console users and their respective Computer Group rights.
CCI Reference
CCI-000213- Created
- 2026-04-07 20:08:37
- Last Updated
- 2026-04-07 20:08:37