Skip to content

Using OpenSCAP to audit against new RHEL 8 V1R13 STIG #11557

Closed Answered by Mab879
permanentdaylight asked this question in Q&A
Discussion options

You must be logged in to vote

Thanks for the question and I'm glad that this project is helpful to you.

The STIG profile in the ssg-rhel8-ds.xml file is not directly based on the SCAP (or any other) automated content that DISA provides. It based on the interpretation of the manual SCAP content (the wording of the STIG) by the developers from this project. The developers of this project come the OS vendors (such as Red Hat, SUSE, Oracle, Canonical, among others) and community members who contribute content. We create the OVAL checks, the remedations (Bash, Ansible, etc), and the prose used the ssg-rhel8-ds.xml.

As for the updates from V1R13 for RHEL 8 those were done in #11478 and will be in the in v0.1.72 release of t…

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by permanentdaylight
Comment options

You must be logged in to vote
1 reply
@Mab879
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants