Support #378
Updated by Charles N 1 day ago
Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance). Central funnel for all bookmarks / repos / blog posts related to CMMC, FedRAMP, and compliance hardening. Each source is triaged and routed to the relevant child ticket. ## Scope - [ ] Collect and catalog all existing bookmarks/repos/blog posts - [ ] Upstream sources to triage (from parent): - https://github.com/JAKTOOL/cmmc - https://github.com/guardian-nexus/AuditKit-Community-Edition - https://github.com/abualialfatih23/PVE-9-Hardening - https://github.com/HomeSecExplorer/Proxmox-Hardening-Guide - https://github.com/ansible-lockdown/DEBIAN12-CIS - https://github.com/ovh/debian-cis - https://www.cisecurity.org/benchmark/debian_linux - https://github.com/ComplianceAsCode/content - https://www.open-scap.org/security-policies/scap-security-guide/ - https://www.cmmcaudit.org/ - [ ] Route each source to the appropriate child ticket ## Research items - **Lynis support status:** verify whether Lynis is still actively maintained (CISOfy/lynis repo activity, release cadence). Decide keep or remove. - **Audit tool inventory:** catalog audit/scanning tools beyond lynis (e.g. ssh-audit, others) and decide which to standardize on. ## Context - AWX (tsys-awx) is the ansible execution hub for all KNELIAC roles. - Wazuh VM is stood up; provides SCA visibility. - kali-tsys VM is stood up for offensive/audit tooling. ## Dependencies No dependencies. Feeds findings into #383 #5 (audit tooling) and other children.