Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Norm-Audit-Hardening-Audit #76

Closed
bbaassssiiee opened this issue Apr 6, 2016 · 7 comments
Closed

Norm-Audit-Hardening-Audit #76

bbaassssiiee opened this issue Apr 6, 2016 · 7 comments

Comments

@bbaassssiiee
Copy link

bbaassssiiee commented Apr 6, 2016

This project lacks a normative specification that can be used as a benchmark in an audit. If it would use CIS or DISA then we can use oscap to verify hardening deviations. Now the sysop did something without a standard to comply to.

@chris-rock
Copy link
Member

@bbaassssiiee We are happy to add that support. PRs are very welcome to move into that direction

@naman
Copy link

naman commented Jan 28, 2019

It will be great if the maintainers could look again at this issue. OP has a point. A security baseline standard like CIS should be a norm for auditing purposes.

Thanks

@rndmh3ro rndmh3ro reopened this Feb 2, 2019
@rndmh3ro
Copy link
Member

rndmh3ro commented Feb 2, 2019

I'm going to let this open so someone can work on this, if he or she wants to.

@Rockstar04
Copy link
Member

This as well as the other dev-sec os-hardening projects are all benchmarked against he dev-sec/linux-baseline. While it is not a 1-1 clone of the CIS or DISA, it does cover many of their security checks.

I would suggest closing this issue, and addressing the topic of standard security benchmarks there, so they can benefit all the dev-sec projects.

@naman
Copy link

naman commented Feb 13, 2019

That's a great suggestion @Rockstar04. I'll open an issue there. Thanks

@Rockstar04
Copy link
Member

Closed in favor of dev-sec/linux-baseline#110

@bbaassssiiee
Copy link
Author

bbaassssiiee commented Feb 13, 2019

I will not create a PR here, I already contributed to repositories supported by AnsibleLockdown.io:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants