The Tanium documentation identifying recognized and trusted OVAL feeds must be maintained.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-254892
TANS-AP-000155
SV-254892r960804_rule
Medium
Description
OVAL XML documents are provided from several possible sources such as the CIS open source repository, or any number of vendor/third-party paid repositories. These documents are used to automate the passive validation of vulnerabilities on systems and therefore require a reasonable level of confidence in their origin. Nonapproved OVAL definitions lead to a false sense of security when evaluating an enterprise environment.