Actions
Support #378
openSupport #311: OAM - Security Hardening Auditing and Compliance
OAM: Compliance source intake & triage
Support #378:
OAM: Compliance source intake & triage
Start date:
08/06/2026
Due date:
% Done:
0%
Estimated time:
Description
Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance).
Central funnel for all bookmarks / repos / blog posts related to CMMC, FedRAMP, and compliance hardening. Each source is triaged and routed to the relevant child ticket.
Scope¶
- Collect and catalog all existing bookmarks/repos/blog posts
- Upstream sources to triage (from parent):
- https://github.com/JAKTOOL/cmmc
- https://github.com/guardian-nexus/AuditKit-Community-Edition
- https://github.com/abualialfatih23/PVE-9-Hardening
- https://github.com/HomeSecExplorer/Proxmox-Hardening-Guide
- https://github.com/ansible-lockdown/DEBIAN12-CIS
- https://github.com/ovh/debian-cis
- https://www.cisecurity.org/benchmark/debian_linux
- https://github.com/ComplianceAsCode/content
- https://www.open-scap.org/security-policies/scap-security-guide/
- https://www.cmmcaudit.org/
- Route each source to the appropriate child ticket
Research items¶
- Lynis support status: verify whether Lynis is still actively maintained (CISOfy/lynis repo activity, release cadence). Decide keep or remove.
- Audit tool inventory: catalog audit/scanning tools beyond lynis (e.g. ssh-audit, others) and decide which to standardize on.
Context¶
- AWX (tsys-awx) is the ansible execution hub for all KNELIAC roles.
- Wazuh VM is stood up; provides SCA visibility.
- kali-tsys VM is stood up for offensive/audit tooling.
Dependencies¶
No dependencies. Feeds findings into #383 (audit tooling) and other children.
Actions