{"repo":"ansible-lockdown/UBUNTU18-CIS","free":true,"listed":false,"github":"https://github.com/ansible-lockdown/UBUNTU18-CIS","clone":"git clone https://github.com/ansible-lockdown/UBUNTU18-CIS.git","description":"Ansible CIS Benchmark Compliance Remediation for UBUNTU18","language":"YAML","stars":31,"topics":["ansible-role","cis","cis-benchmark","ansible-playbook","automation","cis-compliance","cis-hardening","cis-security","configuration-management","cybersecurity"],"license":"MIT","category":"security-tools","readme_excerpt":"UBUNTU18 CIS Configure a Ubuntu18 machine to be CIS compliant Based on CIS Ubuntu1804 Benchmark v2.1.0 --- --- Looking for support? Lockdown Enterprise Ansible support Community Join us on our Discord Server to ask questions, discuss features, or just chat with other Ansible-Lockdown users. --- Caution(s) This role will make changes to the system which may have unintended consequences. This is not an auditing tool but rather a remediation tool to be used after an audit has been conducted. Check Mode is not supported! The role will complete in check mode without errors, but it is not supported and should be used with caution. The UBUNTU18-CIS-Audit role or a compliance scanner should be used for compliance checking over check mode. This role was developed against a clean install of the Operating System. If you are implementing to an existing system please review this role for any site specific changes that are needed. To use release version please point to main branch and relevant release for the cis benchmark you wish to work with. --- Matching a security Level for CIS It is possible to to only run level 1 or level 2 controls for CIS. This is managed using tags: - level1 server - level1 workstation - level2 server - level2 workstation The control found in defaults main also need to reflect this as this control the testing thet takes place if you are using the audit component. Coming from a previous release CIS release always contains changes, it is highly recommended to revie","default_branch":null,"files":null,"tree":[],"storefront":"/r/ansible-lockdown","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ansible-lockdown/UBUNTU18-CIS/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}