The scanning tools
Before we dive into the Playbook, let’s quickly look at the three tools we will be running, starting with the one that does the most, OpenSCAP.
OpenSCAP
First, we will be looking at one of Red Hat’s tools, called OpenSCAP. Before we continue, the next section will contain many abbreviations.
So, what is SCAP? The Security Content Automation Protocol (SCAP) is an open standard that encompasses several components, all of which are open standards themselves, to build a framework that allows you to automatically assess and remediate your hosts against the National Institute of Standards and Technology (NIST) Special Publication 800-53.
This publication is a catalog of controls applied to all U.S. federal IT systems, apart from those maintained by the National Security Agency (NSA). These controls have been effected to help implement the Federal Information Security Management Act (FISMA) of 2002 across U.S. federal departments.
SCAP is made...