Automated CIS Benchmark Compliance Audit for Ubuntu 24 with Ansible & GOSS
Go to file
uk-bolly 66ae34de32
Merge pull request #8 from ansible-lockdown/meta_fixes
meta updates
2025-01-21 16:17:21 +00:00
section_1 meta updates 2025-01-21 07:58:29 +00:00
section_2 fixed typo 2025-01-10 11:50:24 +00:00
section_3 meta updates 2025-01-21 07:58:29 +00:00
section_4 initial v1.0.0 2024-09-05 08:17:35 +01:00
section_5 meta updates 2025-01-21 07:58:29 +00:00
section_6 meta updates 2025-01-21 07:58:29 +00:00
section_7 initial v1.0.0 2024-09-05 08:17:35 +01:00
vars updated time pool layout 2025-01-10 08:26:23 +00:00
.gitattributes initial v1.0.0 2024-09-05 08:17:35 +01:00
.gitignore initial v1.0.0 2024-09-05 08:17:35 +01:00
CONTRIBUTING.md initial v1.0.0 2024-09-05 08:17:35 +01:00
Changelog.md initial v1.0.0 2024-09-05 08:17:35 +01:00
LICENSE initial v1.0.0 2024-09-05 08:17:35 +01:00
README.md Updted to new layout more links to RTD 2024-10-24 05:51:37 +01:00
goss.yml initial v1.0.0 2024-09-05 08:17:35 +01:00
run_audit.sh udpated script 2024-12-06 14:14:07 +00:00

README.md

Ubuntu 24.04 Goss config

Overview

Based on CIS Benchmark for Ubuntu 24.04 LTS Benchmark v1.0.0

Centre For Internet Security

This repository is set of configuration files and directories to run the audit of the relevant benchmark of Ubuntu 24.04 servers

This is configured in a directory structure level.

variables

file: vars/{benchmark_type}.yml

Please refer to the file for all options and their meanings

The listed variable for every control/benchmark can be turned on/off or section

  • Other controls

    • enable_selinux
    • run_heavy_tasks
  • Bespoke options

    If a site has specific options e.g. password complexity these can also be set.

Requirements

goss >= 0.4.4 root privileges

Branches

If running as part of the ansible playbook, this will pull in the relevant branch for the version of benchmark you are remediating.

  • e.g. v1.0.0 will pull in branch benchmark-v1.0.0

Devel is normally the latest benchmark version, so maybe different from the version of benchmark you wish to test. Details will show in the README as part of the remedation as to the benchmark for the version it is written for.

Usage

Fot the latest information on audit and how it can be used please visit

Read the Docs - Audit

Extra settings

Ability to add your own requirements is available in several sections

Support

Discord Community Discussions

Enterprise Support

MindPoint Group