The Tanium documentation identifying recognized and trusted OVAL feeds must be maintained.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-234117
TANS-SV-000051
SV-234117r612749_rule
Medium
Description
OVAL XML documents are provided from several possible sources such as the CIS open source repository, or any number of vendor/3rd party paid repositories. These documents are used to automate the passive validation of vulnerabilities on systems and therefore require a reasonable level of confidence in their origin. Non-approved OVAL definitions lead to a false sense of security when evaluating an enterprise environment.