Custom Compliance Reporting - Tanium Tech Talks #109

Custom Compliance Reporting - Tanium Tech Talks #109

Oct 23, 2024

Learn how to build your own custom audit compliance reports with Tanium Comply. Do you have configuration audits in your IT shop? Does that involve painful screenshots and spreadsheets. We're going to show you how to automate your own audits and even schedule the reports to be delivered automatically.

  • ISO27001, NIST 800-x, SOC2, NIS2, HIPAA, GDPR, PCI, CMMC, FISMA, DISA STIGs, etc.
  • Leverage CIS benchmarks as a baseline
  • Tune CIS benchmarks to your own values
  • Create custom checks unique to your internal standards
  • Compile all of these into your own automated reports and dashboards

#informationsecurity #informationtechnology #compliance #audit #ISO27001 #NIST #SOC2 #NIS2 #HIPAA #GDPR #PCI #CMMC #FISMA #DISA #STIG

RESOURCES
Docs maturity matrix for Comply
https://help.tanium.com/bundle/ug_comply_cloud/page/comply/gaining_org_effectiveness.html#op_metrics
Docs for customizing Comply
https://help.tanium.com/bundle/ug_comply_cloud/page/comply/comp_custom.html
Tanium Connect for exporting and sending reports
https://www.youtube.com/watch

CHAPTERS

00:00 Intro

01:10 Meet Alysson

02:02 What is the problem we're solving?

03:20 Where do I start?

05:22 What is the benefit?

06:50 DEMO Customize CIS benchmarks

10:40 Policy naming standards

11:35 DEMO Create custom checks

16:50 Best practice: light scripting

17:53 DEMO Add my script as a custom check

19:57 DEMO Custom assessments

23:33 Scan frequency

24:50 Custom assessment profiles

26:00 DEMO Custom standard mappings

33:40 DEMO Custom reports

36:00 DEMO Export reports automatically

38:09 Summary

38:35 DEMO Custom dashboards

40:50 Wrap up & resources