forked from ansible-lockdown/RHEL9-CIS
Added Nist values
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
This commit is contained in:
parent
8b58d71e4b
commit
2bf67cde0d
16 changed files with 100 additions and 21 deletions
|
|
@ -9,6 +9,8 @@
|
|||
- level1-workstation
|
||||
- patch
|
||||
- rule_1.3.1.1
|
||||
- NIST800-53R5_AC-3
|
||||
- NIST800-53R5_MP-2
|
||||
ansible.builtin.package:
|
||||
name: libselinux
|
||||
state: present
|
||||
|
|
@ -23,6 +25,8 @@
|
|||
- scored
|
||||
- patch
|
||||
- rule_1.3.1.2
|
||||
- NIST800-53R5_AC-3
|
||||
- NIST800-53R5_MP-2
|
||||
ansible.builtin.replace:
|
||||
path: /etc/default/grub
|
||||
regexp: '{{ item }}'
|
||||
|
|
@ -45,6 +49,8 @@
|
|||
- selinux
|
||||
- patch
|
||||
- rule_1.3.1.3
|
||||
- NIST800-53R5_AC-3
|
||||
- NIST800-53R5_MP-2
|
||||
ansible.posix.selinux:
|
||||
conf: /etc/selinux/config
|
||||
policy: "{{ rhel9cis_selinux_pol }}"
|
||||
|
|
@ -60,6 +66,8 @@
|
|||
- selinux
|
||||
- patch
|
||||
- rule_1.3.1.4
|
||||
- NIST800-53R5_AC-3
|
||||
- NIST800-53R5_MP-2
|
||||
ansible.posix.selinux:
|
||||
conf: /etc/selinux/config
|
||||
policy: "{{ rhel9cis_selinux_pol }}"
|
||||
|
|
@ -76,6 +84,8 @@
|
|||
- selinux
|
||||
- patch
|
||||
- rule_1.3.1.5
|
||||
- NIST800-53R4_AC-3
|
||||
- NIST800-53R4_SI-6
|
||||
ansible.posix.selinux:
|
||||
conf: /etc/selinux/config
|
||||
policy: "{{ rhel9cis_selinux_pol }}"
|
||||
|
|
@ -91,6 +101,8 @@
|
|||
- audit
|
||||
- services
|
||||
- rule_1.3.1.6
|
||||
- NIST800-53R5_AC-3
|
||||
- NIST800-53R5_MP-2
|
||||
vars:
|
||||
warn_control_id: '1.3.1.6'
|
||||
block:
|
||||
|
|
@ -118,6 +130,8 @@
|
|||
- level1-workstation
|
||||
- patch
|
||||
- rule_1.3.1.7
|
||||
- NIST800-53R5_AC-3
|
||||
- NIST800-53R5_MP-2
|
||||
ansible.builtin.package:
|
||||
name: mcstrans
|
||||
state: absent
|
||||
|
|
@ -134,3 +148,5 @@
|
|||
- selinux
|
||||
- patch
|
||||
- rule_1.3.1.8
|
||||
- NIST800-53R5_AC-3
|
||||
- NIST800-53R5_MP-2
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue