Applying OpenSCAP policies with oscap
SCAP, the Security Content Automation Protocol (SCAP), was created by the U.S. National Institute of Standards and Technology. It consists of hardening guides, hardening templates, and baseline configuration guides for setting up secure systems. OpenSCAP is a set of free open source software tools that can be used to implement SCAP. It consists of the following:
- Security profiles that you can apply to a system. There are different profiles for meeting the requirements of several different certifying agencies.
- Security guides to help with the initial setup of your system.
- The
oscap
command-line utility to apply security templates. - On Red Hat-type systems that have a desktop interface, you have SCAP Workbench, a GUI-type utility.
You can install OpenSCAP on either the Red Hat or the Ubuntu distros, but it's much better implemented on the Red Hat distros. For one thing, the Red Hat world has the very cool SCAP Workbench, but the Ubuntu world doesn't. When you...