Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Restructure the CIS and DISA STIG hardening guides #890

Merged
merged 17 commits into from
Dec 16, 2024

Conversation

ktsakalozos
Copy link
Member

  • rename the CIS and DISA STIG hardening pages to assessments
  • include the DISA STIG assessment report
  • have the post-deployment hardening steps in one place
  • CIS assessment page includes all the checks

@ktsakalozos ktsakalozos requested a review from a team as a code owner December 11, 2024 10:57
Copy link
Contributor

@bschimke95 bschimke95 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@bschimke95
Copy link
Contributor

most spell-checker errors seem unrelated but "unsecure" should probably be "insecure"
https://github.com/canonical/k8s-snap/actions/runs/12275066803/job/34249339507?pr=890#step:4:27

Copy link
Contributor

@aznashwan aznashwan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor comments; most are to myself and I'll address them in the DISA checker tool ASAP.

@ktsakalozos note that a couple of the footer links are either obsolete/not pointing to pages that exist [yet]

docs/src/snap/howto/security/hardening.md Outdated Show resolved Hide resolved
docs/src/snap/howto/security/index.md Outdated Show resolved Hide resolved
@aznashwan
Copy link
Contributor

aznashwan commented Dec 11, 2024

most spell-checker errors seem unrelated but "unsecure" should probably be "insecure"

@bschimke95 correct, though unfortunately all 3 of those instances of "unsecure" are from text sourced verbatim from the upstream Findings defs (V-242451, V-242466, V-242467)

I had noticed them when first implementing the checker and had a decent laugh (presume they're all written by the same DISA employee); but considering we'll be hosting these ourselves now, I'll have the tool update them so we don't look bad too.

LE: re-reading the descriptions of each, I'll give the guy the benefit of the doubt and assume they're probably a typo for unsecureD (they're all paired with and compromiseD)

@eaudetcobello eaudetcobello force-pushed the fix/hardening-compliance branch from 413a275 to 67fa0b4 Compare December 11, 2024 20:09
fixed broken links and removed unneeded ones. Reverted changes to .wordlist - it should not be altered. Fixed index page to show CIS on navbar
@nhennigan nhennigan dismissed aznashwan’s stale review December 16, 2024 17:19

Changes that were requested were reviewed and either implemented or marked won't do.

@nhennigan nhennigan merged commit 28919a2 into main Dec 16, 2024
6 checks passed
@nhennigan nhennigan deleted the fix/hardening-compliance branch December 16, 2024 17:21
HomayoonAlimohammadi pushed a commit that referenced this pull request Feb 4, 2025
* Restructure the CIS and DISA STIG hardening guides

* Fix spelling errors

---------

Co-authored-by: Etienne Audet-Cobello <[email protected]>
Co-authored-by: nhennigan <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants