Skip to content
 
 

Repository files navigation

Siperal Bozkaros CIS RHEL10 Server Level 1/2

Configures a Siperal Bozkaros (RHEL10, Rocky derivative) machine to be CIS compliant.
These controls only supports RHEL family 10.

Supported Controls:

  1. Server Level 1
  2. Server Level 2

This role will make changes to the system which may have unintended consequences. This is not an auditing tool but rather a remediation tool to be used after an audit has been conducted.

  • Testing is the most important thing you can do.
  • Check Mode is not guaranteed!
  • This role was developed against a clean install of the Operating System. If you are implementing to an existing system please review this role for any site specific changes that are needed.

Rules

Skip

  • 1.8.x: There is no desktop environment for Siperal Bozkaros

Target System

Technical Dependencies

  • Python 3.8+
  • Ansible 2.12+
  • python-def
  • libselinux-python
  • goss binary required for auditing
  • passlib

Format

Conversion Format for NIST References:

  1. Standard Prefix:
    • All references are prefixed with "NIST".
  2. Standard Types:
    • "800-53" references are formatted as NIST800-53.
    • "800-53r5" references are formatted as NIST800-53R5 (with 'R' capitalized).
    • "800-171" references are formatted as NIST800-171.
  3. Details:
    • Section and subsection numbers use periods (.) for numeric separators.
    • Parenthetical elements are separated by underscores (_), e.g., IA-5(1)(d) becomes IA-5_1_d.
    • Subsection letters (e.g., "b") are appended with an underscore.

Credits and Thanks

  • Original Authors:
    Mark Bolwell, George Nalen, Steve Williams, Fred Witty
  • Forked from:
    ansible-lockdown

About

Automated CIS Benchmark Compliance Remediation for Siperal Bozkaros with Ansible

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Contributors

Languages