Actions
Support #382
openSupport #311: OAM - Security Hardening Auditing and Compliance
OAM: STIG/SCAP compliance
Support #382:
OAM: STIG/SCAP compliance
Start date:
08/06/2026
Due date:
% Done:
0%
Estimated time:
Description
Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance).
Implement STIG/SCAP compliance tooling and controls, expanding the existing security_scap_stig KNELIAC role and building out the STIG/CMMC control library.
Scope¶
- Install SCAP Security Guide packages:
apt install ssg-base ssg-debderived ssg-debian ssg-nondebian ssg-applications - Utilize ansible to run relevant playbooks from https://github.com/ComplianceAsCode/content
- Expand security_scap_stig role (GRUB perms, modprobe blacklist, login banners, cron/at perms - partially done)
- Build out STIG/CMMC compliance control library
- Validate in sectestbed-* before prod
Context¶
- Reference: https://www.open-scap.org/security-policies/scap-security-guide/
- Roles executed via tsys-awx (AWX).
Dependencies¶
Depends on #379 (test lab), #381 (CIS baseline). Blocks #383 (audit tooling), #389 (Greenbone).
Updated by Charles N 1 day ago
- Blocked by Support #381: OAM: CIS Benchmark hardening (Debian 13 trixie) added
Updated by Charles N 1 day ago
- Blocks Support #383: OAM: Audit tooling selection & deployment added
Updated by Charles N 1 day ago
- Blocks Support #389: OAM: Greenbone Vulnerability Manager (kali-tsys) added
Actions