OpenSCAP and its related tools are by themselves engines—they cannot actually help you to audit your environment without a security policy against which to scan. As we explored in Chapter 13, Using CIS Benchmarks, there are numerous security standards for Linux, and in this book, we have considered in depth the CIS Benchmarks. Sadly, this standard is not currently available for audit through OpenSCAP, though many other security policies are that would be well suited to securing your infrastructure. Also, as OpenSCAP and its policies are entirely open source, there is nothing to stop you from creating your own policy for whatever requirements you have.
There are plenty of security standards available for you to freely download and audit your infrastructure against, and in the next section, we will look at the primary one that you will most...