{"repo":"ansible-lockdown/UBUNTU20-CIS-Audit","free":true,"listed":false,"github":"https://github.com/ansible-lockdown/UBUNTU20-CIS-Audit","clone":"git clone https://github.com/ansible-lockdown/UBUNTU20-CIS-Audit.git","description":"CIS Benchmark Compliance Audit for UBUNTU20 with Ansible & GOSS","language":"YAML","stars":17,"topics":["cis","cis-benchmark","ansible","ansible-playbook","ansible-role","automation","cis-compliance","cis-hardening","cis-security","configuration-management"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"Ubuntu 20 Goss config Overview Based on CIS Benchmark for Ubuntu 20.04 LTS Benchmark v3.0.0 [Centre For Internet Security] This repository is set of configuration files and directories to run the audit of the relevant benchmark of Ubuntu 20.04 servers This is configured in a directory structure level. variables file: vars/{benchmark type}.yml Please refer to the file for all options and their meanings The listed variable for every control/benchmark can be turned on/off or section - Other controls - enable selinux - run heavy tasks - Bespoke options If a site has specific options e.g. password complexity these can also be set. Requirements goss = 0.4.4 root privileges Branches If running as part of the ansible playbook, this will pull in the relevant branch for the version of benchmark you are remediating. - e.g. v1.0.0 will pull in branch benchmark-v1.0.0 Devel is normally the latest benchmark version, so maybe different from the version of benchmark you wish to test. Details will show in the README as part of the remediation as to the benchmark for the version it is written for. Usage For the latest information on audit and how it can be used please visit [Read the Docs - Audit] Extra settings Ability to add your own requirements is available in several sections Support [Discord Community Discussions] [Enterprise Support] [MindPoint Group] Links and Further information - [Goss] - [Goss documentation] - [Centre For Internet Security] [benchmark-type]: CIS [OS-VERSION]: Ubuntu","default_branch":null,"files":null,"tree":[],"storefront":"/r/ansible-lockdown","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ansible-lockdown/UBUNTU20-CIS-Audit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}