OpenSCAP content for SLE 16#684
Conversation
lvicoun
left a comment
There was a problem hiding this comment.
Hi Souvik,
please see my suggestions. Thanks!
lvicoun
left a comment
There was a problem hiding this comment.
Hi Souvik,
LGTM. Thanks!
dariavladykina
left a comment
There was a problem hiding this comment.
Hi, please see some suggestions here. Thanks!
| xmlns:xlink="http://www.w3.org/1999/xlink" | ||
| xmlns:trans="http://docbook.org/ns/transclusion"> | ||
| <info> | ||
| <title>Overview</title> |
There was a problem hiding this comment.
I would remove the first 2 paragraphs here - they are explained in section 2 - and just leave "The following sections describe...", and add a para in front of it saying sth like: This article explains how to use &oscap; and SSG to audit and harden &suselinunx; systems against recognized security baselines.
| <listitem> | ||
| <para> | ||
| &openscap; is an open source toolset that implements the Security Content | ||
| Automation Protocol (SCAP) framework. Combined with the &ssg;, it enables automated |
There was a problem hiding this comment.
I'd add the SSG explained here to safely use the abbreviation later:
| Automation Protocol (SCAP) framework. Combined with the &ssg;, it enables automated | |
| Automation Protocol (SCAP) framework. Combined with the &ssg; (SSG), it enables automated |
| <!-- Introductory glue: sets context and outlines the workflow --> | ||
| <module resourceref="_openscap-intro" renderas="section"> | ||
| <merge> | ||
| <title>Overview</title> |
There was a problem hiding this comment.
Maybe a more descriptive heading? I also suggested to change the structure down in the file.
| <title>Overview</title> | |
| <title>Auditing and hardening &suselinux; with &openscap;</title> |
| xmlns:xlink="http://www.w3.org/1999/xlink" | ||
| xmlns:trans="http://docbook.org/ns/transclusion"> | ||
| <info> | ||
| <title>Preparing the IT Infrastructure</title> |
There was a problem hiding this comment.
| <title>Preparing the IT Infrastructure</title> | |
| <title>Preparing the IT infrastructure</title> |
| </para> | ||
| </section> | ||
| <section xml:id="openscap-infrastructure-preparing-procedure"> | ||
| <title>Preparation steps</title> |
There was a problem hiding this comment.
| <title>Preparation steps</title> | |
| <title>What pre-hardening steps should you follow?</title> |
| Automated scanning and remediation reduces manual effort, ensures consistent policy | ||
| enforcement across systems, and supports compliance with regulations such as HIPAA, | ||
| PCI-DSS v4, and ANSSI-BP-028. |
There was a problem hiding this comment.
| Automated scanning and remediation reduces manual effort, ensures consistent policy | |
| enforcement across systems, and supports compliance with regulations such as HIPAA, | |
| PCI-DSS v4, and ANSSI-BP-028. | |
| Automated scanning and remediation reduce manual effort, ensure consistent policy | |
| enforcement across systems, and support compliance with regulations such as HIPAA, | |
| PCI-DSS v4 and ANSSI-BP-028. |
| SCAP consists of the following components, which interact with each other to describe, | ||
| evaluate, and report on the security state of a system. |
There was a problem hiding this comment.
| SCAP consists of the following components, which interact with each other to describe, | |
| evaluate, and report on the security state of a system. | |
| SCAP consists of the following components, which interact to describe, | |
| evaluate and report on the security state of a system. |
| </procedure> | ||
| <note> | ||
| <para> | ||
| Remediation must be run more than once. Rules are applied in alphabetical order, some rules |
There was a problem hiding this comment.
| Remediation must be run more than once. Rules are applied in alphabetical order, some rules | |
| Remediation must be run more than once. Rules are applied in alphabetical order. Some rules |
| <itemizedlist> | ||
| <listitem> | ||
| <para> | ||
| Run remediation more than once. Rules are applied in alphabetical order, dependencies |
There was a problem hiding this comment.
| Run remediation more than once. Rules are applied in alphabetical order, dependencies | |
| Run remediation more than once. Rules are applied in alphabetical order. Dependencies |
| xmlns:xlink="http://www.w3.org/1999/xlink" | ||
| xmlns:trans="http://docbook.org/ns/transclusion"> | ||
| <info> | ||
| <title>What's Next</title> |
There was a problem hiding this comment.
| <title>What's Next</title> | |
| <title>What's next</title> |
| <section xml:id="openscap-system-scanning-remote-resources"> | ||
| <title>Using remote resources during a scan</title> | ||
| <para> | ||
| Some &ssg; content references external OVAL files, for example to check whether the system is |
There was a problem hiding this comment.
| Some &ssg; content references external OVAL files, for example to check whether the system is | |
| Some &ssg; content references external OVAL files, for example, to check whether the system is |
PR creator: Description
OpenSCAP content for SLE 16.
PR creator: Are there any relevant issues/feature requests?
PR reviewer: Checklist for editorial review
Apart from the usual checks, please double-check also the following: