Skip to content

Questions about identifiers and references in rule.yml #12300

Answered by Mab879
yu410621 asked this question in Q&A
Discussion options

You must be logged in to vote

Thanks for your interest in the project

For identifiers are added manually for select distributions mainly RHEL and SLE. They are only needed if you adding a rule to these distributions.

As for references these are added based on what security standard the rule is based on / covers. For example, cis@rhel8 comes from the CIS benchmark for RHEL 8. Those are usually manually added. But some polices like the STIG for RHEL 9 use automated assignment of the references.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@yu410621
Comment options

Answer selected by yu410621
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants