{"repo":"ansible-lockdown/RHEL7-STIG","free":true,"listed":false,"github":"https://github.com/ansible-lockdown/RHEL7-STIG","clone":"git clone https://github.com/ansible-lockdown/RHEL7-STIG.git","description":"Automated STIG Benchmark Compliance Remediation for RHEL 7 with Ansible","language":"YAML","stars":282,"topics":["ansible-role","rhel7","ansible","ansible-playbook","automation","configuration-management","cybersecurity","enterprise-hardening","it-compliance","linux-hardening"],"license":"MIT","category":"security-tools","readme_excerpt":"RHEL 7 DISA STIG Configure a RHEL7 based system to be complaint with Disa STIG RHEL7 is End-Of-Life This has now been archived by DISA STIG This may require further testing if run a clean system This role is based on RHEL 7 DISA STIG: Version 3, Rel 15 released on July 24, 2024. --- --- Looking for support? Lockdown Enterprise Ansible support Community On our Discord Server to ask questions, discuss features, or just chat with other Ansible-Lockdown users --- Configure a RHEL 7 system to be DISA STIG compliant. Non-disruptive CAT I, CAT II, and CAT III findings will be corrected by default. Disruptive finding remediation can be enabled by setting rhel7stig disruption high to true . Caution(s) This role will make changes to the system which may have unintended consequences. This is not an auditing tool but rather a remediation tool to be used after an audit has been conducted. Check Mode is not supported! The role will complete in check mode without errors, but it is not supported and should be used with caution. The RHEL7-STIG-Audit role or a compliance scanner should be used for compliance checking over check mode. This role was developed against a clean install of the Operating System. If you are implementing to an existing system please review this role for any site specific changes that are needed. To use release version please point to main branch and relevant release for the cis benchmark you wish to work with. --- Updating Coming from a previous release. As with all re","default_branch":null,"files":null,"tree":[],"storefront":"/r/ansible-lockdown","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ansible-lockdown/RHEL7-STIG/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}