Skip to content

OpenSCAP content for SLE 16#684

Open
sounix000 wants to merge 3 commits into
mainfrom
ssarkar/openscap-sle-16
Open

OpenSCAP content for SLE 16#684
sounix000 wants to merge 3 commits into
mainfrom
ssarkar/openscap-sle-16

Conversation

@sounix000

Copy link
Copy Markdown
Contributor

PR creator: Description

OpenSCAP content for SLE 16.

PR creator: Are there any relevant issues/feature requests?

  • bsc#...
  • jsc#...

PR reviewer: Checklist for editorial review

Apart from the usual checks, please double-check also the following:

@lvicoun lvicoun left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi Souvik,
please see my suggestions. Thanks!

Comment thread articles/openscap-system-hardening.asm.xml Outdated
Comment thread articles/openscap-system-hardening.asm.xml Outdated
Comment thread articles/openscap-system-hardening.asm.xml Outdated
Comment thread tasks/openscap-system-remediating.xml
Comment thread tasks/openscap-system-remediating.xml Outdated
Comment thread tasks/openscap-system-remediating.xml Outdated

@lvicoun lvicoun left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi Souvik,
LGTM. Thanks!

@dariavladykina dariavladykina left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi, please see some suggestions here. Thanks!

Comment thread glues/openscap-intro.xml
xmlns:xlink="http://www.w3.org/1999/xlink"
xmlns:trans="http://docbook.org/ns/transclusion">
<info>
<title>Overview</title>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would remove the first 2 paragraphs here - they are explained in section 2 - and just leave "The following sections describe...", and add a para in front of it saying sth like: This article explains how to use &oscap; and SSG to audit and harden &suselinunx; systems against recognized security baselines.

<listitem>
<para>
&openscap; is an open source toolset that implements the Security Content
Automation Protocol (SCAP) framework. Combined with the &ssg;, it enables automated

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd add the SSG explained here to safely use the abbreviation later:

Suggested change
Automation Protocol (SCAP) framework. Combined with the &ssg;, it enables automated
Automation Protocol (SCAP) framework. Combined with the &ssg; (SSG), it enables automated

<!-- Introductory glue: sets context and outlines the workflow -->
<module resourceref="_openscap-intro" renderas="section">
<merge>
<title>Overview</title>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe a more descriptive heading? I also suggested to change the structure down in the file.

Suggested change
<title>Overview</title>
<title>Auditing and hardening &suselinux; with &openscap;</title>

xmlns:xlink="http://www.w3.org/1999/xlink"
xmlns:trans="http://docbook.org/ns/transclusion">
<info>
<title>Preparing the IT Infrastructure</title>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
<title>Preparing the IT Infrastructure</title>
<title>Preparing the IT infrastructure</title>

</para>
</section>
<section xml:id="openscap-infrastructure-preparing-procedure">
<title>Preparation steps</title>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
<title>Preparation steps</title>
<title>What pre-hardening steps should you follow?</title>

Comment on lines +117 to +119
Automated scanning and remediation reduces manual effort, ensures consistent policy
enforcement across systems, and supports compliance with regulations such as HIPAA,
PCI-DSS v4, and ANSSI-BP-028.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Automated scanning and remediation reduces manual effort, ensures consistent policy
enforcement across systems, and supports compliance with regulations such as HIPAA,
PCI-DSS v4, and ANSSI-BP-028.
Automated scanning and remediation reduce manual effort, ensure consistent policy
enforcement across systems, and support compliance with regulations such as HIPAA,
PCI-DSS v4 and ANSSI-BP-028.

Comment on lines +53 to +54
SCAP consists of the following components, which interact with each other to describe,
evaluate, and report on the security state of a system.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
SCAP consists of the following components, which interact with each other to describe,
evaluate, and report on the security state of a system.
SCAP consists of the following components, which interact to describe,
evaluate and report on the security state of a system.

</procedure>
<note>
<para>
Remediation must be run more than once. Rules are applied in alphabetical order, some rules

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Remediation must be run more than once. Rules are applied in alphabetical order, some rules
Remediation must be run more than once. Rules are applied in alphabetical order. Some rules

<itemizedlist>
<listitem>
<para>
Run remediation more than once. Rules are applied in alphabetical order, dependencies

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Run remediation more than once. Rules are applied in alphabetical order, dependencies
Run remediation more than once. Rules are applied in alphabetical order. Dependencies

xmlns:xlink="http://www.w3.org/1999/xlink"
xmlns:trans="http://docbook.org/ns/transclusion">
<info>
<title>What's Next</title>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
<title>What's Next</title>
<title>What's next</title>

<section xml:id="openscap-system-scanning-remote-resources">
<title>Using remote resources during a scan</title>
<para>
Some &ssg; content references external OVAL files, for example to check whether the system is

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Some &ssg; content references external OVAL files, for example to check whether the system is
Some &ssg; content references external OVAL files, for example, to check whether the system is

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants