2 ms·
There are many projects to automate remediations. One in use by the DoD in this area is OpenSCAP (scanner) and Compliance as Code (benchmark content + automated
by cipherboy 3y ago
There are many projects to automate remediations. One in use by the DoD in this area is OpenSCAP (scanner) and Compliance as Code (benchmark content + automated remediations), lead by Red Hat and contributed to by other Linux vendors.
But, despite having a nice three letter acronym, the DoD is not a homogenous unit and so you're bound to get groups doing different things. :-)
- alexjplant 3y ago> Compliance as Code (benchmark content + automated remediations), lead by Red Hat and contributed to by other Linux vendors. Do they also develop these for Microsoft products? Why is none of this automation linked on their official site? I would think that if you wanted a good security culture you'd share these tools as far and wide as possible. I vaguely recall seeing some tools like this in random GitHub repos but it'd be great to see them promulgated by an authority as they might have been able to mitigate the attack vector that the article was talking about.
- cipherboy 3y agoI don't believe Microsoft contributes to this project. There are STIGs available for Windows but presumably any automated hardening by Microsoft is proprietary. Likely a new Powershell automation backend would be necessary. The scanner might work, though. I think part of the dichotomy comes from the general acceptance of these recommendations. STIGs are only really applicable to the US Govt and perhaps a few select groups that do business with them. Even major banks haven't typically adopted them wholesale (like they have with higher FIPS levels for instance). The broader security community has largely written it off as security theater. For the most part the amount of data generated by these recommendations (which is hard to prove and identify concrete threats in real time -- at best for postmortem understanding) and the impact to usability is substantial enough that I agree. Though, having met with many authors of STIG and other benchmarks, their intentions are well-meaning.