{"repo":"ansible-lockdown/UBUNTU20-STIG","free":true,"listed":false,"github":"https://github.com/ansible-lockdown/UBUNTU20-STIG","clone":"git clone https://github.com/ansible-lockdown/UBUNTU20-STIG.git","description":"Automated STIG Benchmark Compliance Remediation for Ubuntu 20 with Ansible","language":"YAML","stars":19,"topics":["ansible","ansible-playbook","ansible-role","automation","configuration-management","cybersecurity","enterprise-hardening","it-compliance","linux-hardening","secure-baseline"],"license":"MIT","category":"security-tools","readme_excerpt":"Ubuntu 20.04 DISA STIG Configure a Ubuntu 20.04 system to be DISA STIG compliant. Based on Ubuntu 20.04 DISA STIG Version 1, Rel 7 released on Jan 26, 2023 --- --- Looking for support? Lockdown Enterprise Ansible support Community Join us on our Discord Server to ask questions, discuss features, or just chat with other Ansible-Lockdown users. --- Caution(s) This role will make changes to the system which may have unintended consequences. This is not an auditing tool but rather a remediation tool to be used after an audit has been conducted. Check Mode is not supported! The role will complete in check mode without errors, but it is not supported and should be used with caution. This role was developed against a clean install of the Ubuntu 20 operating system. If you are implementing to an existing system please review this role for any site specific changes that are needed. To use release version please point to main branch and relevant release for the stig benchmark you wish to work with. --- Matching a security Level for STIG It is possible to to only run controls that are based on a particular for security level for STIG. This is managed using tags: - CAT1 - CAT2 - CAT3 The control found in defaults main also need to reflect true so as this will allow the controls to run when the playbook is launched. Coming from a previous release STIG releases always contain changes, it is highly recommended to review the new references and available variables. This has changed significan","default_branch":null,"files":null,"tree":[],"storefront":"/r/ansible-lockdown","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ansible-lockdown/UBUNTU20-STIG/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}