The Tanium Client - Set Action Lock must be set to OFF during maintenance window timeframes only.

From Tanium 6.5 Security Technical Implementation Guide

Part of SRG-APP-000516

Associated with: CCI-000366

SV-81477r1_rule The Tanium Client - Set Action Lock must be set to OFF during maintenance window timeframes only.

Vulnerability discussion

Set Action Lock On will prevent any managed system from executing Tanium generated actions. This functionality is helpful when needing to eliminate systems from taking actions (e.g. patch scanning/installation, unmanaged asset scanning, updating, etc.), whether it is automatically scheduled upon install or manually scheduled. This functionality can also be used to help debug performance issues on a client if there is a fear that Tanium is running an action that could be causing a negative impact.Setting Action Lock Off will ensure any Tanium generated actions are executed at the endpoint.

Check content

Using a web browser on a system that has connectivity to the Tanium Server, access the Tanium Server web user interface (UI) and log on with CAC. In the “Home” tab, locate the Tanium Administration dashboard. Click on “Client Configuration”. The results will display two windows. One window will show "Clients that can take actions - Action Lock Off" and the other window will show "Clients that cannot take actions - Action Lock On". If any systems are listed in the "Clients that cannot take actions - Action Lock Off" window and it is not an official maintenance window timeframe for those systems, this is a finding.

Fix text

Using a web browser on a system that has connectivity to the Tanium Server, access the Tanium Server web user interface (UI) and log on with CAC. In the “Home” tab, locate the Tanium Administration dashboard. Click on “Client Configuration”. The results will display two windows. One window will show "Clients that can take actions - Action Lock Off" and the other window will show "Clients that cannot take actions - Action Lock On". In the windows displaying systems with Action Lock Off, highlight to select all systems displayed. Right-click and choose "Deploy Action".

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer