Summary
By learning the basics of OpenSCAP, we are ready to review and harden systems to make them compliant with the regulations we need them to run under.
Now if you are requested to comply with any regulatory requisitions, you can find the right SCAP profile for it (or build it if it doesn't exist) and ensure that your systems are fully compliant.
Also, even when no regulatory requirements apply, the use of OpenSCAP can help you find vulnerabilities in the system, or apply a more secure (and restrictive) configuration to your systems in order to reduce the risks.
There are ways to extend our knowledge and skills by learning Ansible and being able to automatically apply changes to our systems in a way that is easy to scale, as well as Red Hat Satellite, which can help run SCAP scans to the whole IT base we are managing even when we could be talking about thousands of systems.
Now that our security skills are improving and being consolidated, let's dive...