Custom Compliance Reporting - Tanium Tech Talks #109
Learn how to build your own custom audit compliance reports with Tanium Comply. Do you have configuration audits in your IT shop? Does that involve painful screenshots and spreadsheets. We're going to show you how to automate your own audits and even schedule the reports to be delivered automatically.
- ISO27001, NIST 800-x, SOC2, NIS2, HIPAA, GDPR, PCI, CMMC, FISMA, DISA STIGs, etc.
- Leverage CIS benchmarks as a baseline
- Tune CIS benchmarks to your own values
- Create custom checks unique to your internal standards
- Compile all of these into your own automated reports and dashboards
#informationsecurity #informationtechnology #compliance #audit #ISO27001 #NIST #SOC2 #NIS2 #HIPAA #GDPR #PCI #CMMC #FISMA #DISA #STIG
RESOURCES
Docs maturity matrix for Comply
https://help.tanium.com/bundle/ug_comply_cloud/page/comply/gaining_org_effectiveness.html#op_metrics
Docs for customizing Comply
https://help.tanium.com/bundle/ug_comply_cloud/page/comply/comp_custom.html
Tanium Connect for exporting and sending reports
https://www.youtube.com/watch
CHAPTERS
00:00 Intro
01:10 Meet Alysson
02:02 What is the problem we're solving?
03:20 Where do I start?
05:22 What is the benefit?
06:50 DEMO Customize CIS benchmarks
10:40 Policy naming standards
11:35 DEMO Create custom checks
16:50 Best practice: light scripting
17:53 DEMO Add my script as a custom check
19:57 DEMO Custom assessments
23:33 Scan frequency
24:50 Custom assessment profiles
26:00 DEMO Custom standard mappings
33:40 DEMO Custom reports
36:00 DEMO Export reports automatically
38:09 Summary
38:35 DEMO Custom dashboards
40:50 Wrap up & resources