{"repo":"ansible-lockdown/RHEL9-CIS-Audit","free":true,"listed":false,"github":"https://github.com/ansible-lockdown/RHEL9-CIS-Audit","clone":"git clone https://github.com/ansible-lockdown/RHEL9-CIS-Audit.git","description":"Automated CIS Benchmark Compliance Audit for RHEL 9 with Ansible & GOSS","language":"YAML","stars":51,"topics":["rhel9","cis-benchmark","ansible","ansible-playbook","ansible-role","automation","cis","cis-compliance","cis-hardening","cis-security"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"RHEL 9 Goss config Overview Based on CIS 2.0.0 Ability to audit a system using a lightweight binary to check the current state. This is: - very small (16 MB) - lightweight - self-contained It works using a set of configuration files and directories to audit CIS benchmarks of RHEL 9 servers. These files/directories correlate to the CIS level and CIS control ID. Tested on - RHEL 9 - Rocky 9 - AlmaLinux 9 - Oracle Linux 9 Requirements You must have goss available on the host you would like to test. You must have sudo/root access to the system, as some commands require elevated privileges. Assuming you have already cloned this repository, you can run goss from where you wish. Please refer to the audit documentation for usage. - readthedocs This also works alongside the Ansible Lockdown RHEL9-CIS role, which will: - install - audit - remediate - audit Join us Join us on our Discord Server to ask questions, discuss features, or just chat with other Ansible-Lockdown users. Set of configuration files and directories to run the first stages of CIS of RHEL 9 servers. This is configured in a directory structure level. Goss is run based on the goss.yml file in the top level directory. This specifies the configuration. Further Information - goss documentation - CIS standards","default_branch":null,"files":null,"tree":[],"storefront":"/r/ansible-lockdown","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ansible-lockdown/RHEL9-CIS-Audit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}