Project

General

Profile

Actions

Support #382

open

Support #311: OAM - Security Hardening Auditing and Compliance

OAM: STIG/SCAP compliance

Support #382: OAM: STIG/SCAP compliance

Added by Charles N 1 day ago. Updated 1 day ago.

Status:
Feedback
Priority:
Normal
Assignee:
Target version:
-
Start date:
08/06/2026
Due date:
% Done:

0%

Estimated time:

Description

Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance).

Implement STIG/SCAP compliance tooling and controls, expanding the existing security_scap_stig KNELIAC role and building out the STIG/CMMC control library.

Scope

  • Install SCAP Security Guide packages:
    apt install ssg-base ssg-debderived ssg-debian ssg-nondebian ssg-applications
  • Utilize ansible to run relevant playbooks from https://github.com/ComplianceAsCode/content
  • Expand security_scap_stig role (GRUB perms, modprobe blacklist, login banners, cron/at perms - partially done)
  • Build out STIG/CMMC compliance control library
  • Validate in sectestbed-* before prod

Context

Dependencies

Depends on #379 (test lab), #381 (CIS baseline). Blocks #383 (audit tooling), #389 (Greenbone).


Related issues 3 (3 open0 closed)

Blocked by Known Element Enterprises - Technology & Facility Services - Support #381: OAM: CIS Benchmark hardening (Debian 13 trixie)FeedbackCharles N08/06/2026

Actions
Blocks Known Element Enterprises - Technology & Facility Services - Support #383: OAM: Audit tooling selection & deploymentFeedbackCharles N08/06/2026

Actions
Blocks Known Element Enterprises - Technology & Facility Services - Support #389: OAM: Greenbone Vulnerability Manager (kali-tsys)FeedbackCharles N08/06/2026

Actions
Actions

Also available in: PDF Atom