Project

General

Profile

Support #378

Updated by Charles N 1 day ago

Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance). 

 Central funnel for all bookmarks / repos / blog posts related to CMMC, FedRAMP, and compliance hardening. Each source is triaged and routed to the relevant child ticket. 

 ## Scope 
 - [ ] Collect and catalog all existing bookmarks/repos/blog posts 
 - [ ] Upstream sources to triage (from parent): 
   - https://github.com/JAKTOOL/cmmc 
   - https://github.com/guardian-nexus/AuditKit-Community-Edition 
   - https://github.com/abualialfatih23/PVE-9-Hardening 
   - https://github.com/HomeSecExplorer/Proxmox-Hardening-Guide 
   - https://github.com/ansible-lockdown/DEBIAN12-CIS 
   - https://github.com/ovh/debian-cis 
   - https://www.cisecurity.org/benchmark/debian_linux 
   - https://github.com/ComplianceAsCode/content 
   - https://www.open-scap.org/security-policies/scap-security-guide/ 
   - https://www.cmmcaudit.org/ 
 - [ ] Route each source to the appropriate child ticket 

 ## Research items 
 - **Lynis support status:** verify whether Lynis is still actively maintained (CISOfy/lynis repo activity, release cadence). Decide keep or remove. 
 - **Audit tool inventory:** catalog audit/scanning tools beyond lynis (e.g. ssh-audit, others) and decide which to standardize on. 

 ## Context 
 - AWX (tsys-awx) is the ansible execution hub for all KNELIAC roles. 
 - Wazuh VM is stood up; provides SCA visibility. 
 - kali-tsys VM is stood up for offensive/audit tooling. 

 ## Dependencies 
 No dependencies. Feeds findings into #383 #5 (audit tooling) and other children. 

Back