Skip to content

Automated STIG Benchmark Compliance Audit for AMAZON Linux 2023 with Ansible & GOSS

License

Notifications You must be signed in to change notification settings

ansible-lockdown/AMAZON2023-STIG-Audit

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

AMAZON2023 STIG Goss config

Overview

Based on STIG Benchmark for AMAZON20203 Benchmark v1r1 - July 2025

DISA STIG

This repository is set of configuration files and directories to run the audit of the relevant benchmark of AMAZON 2023 servers

This is configured in a directory structure level.

variables

file: vars/{benchmark_type}.yml

Please refer to the file for all options and their meanings

The listed variable for every control/benchmark can be turned on/off or section

  • Other controls

    • enable_selinux
    • run_heavy_tasks
  • Bespoke options

    If a site has specific options e.g. password complexity these can also be set.

Requirements

  • goss >= 0.4.9
  • root privileges

Branches

If running as part of the ansible playbook, this will pull in the relevant branch for the version of benchmark you are remediating.

  • e.g. v1.0.0 will pull in branch benchmark-v1.0.0

Devel is normally the latest benchmark version, so maybe different from the version of benchmark you wish to test. Details will show in the README as part of the remediation as to the benchmark for the version it is written for.

Usage

Fot the latest information on audit and how it can be used please visit

Read the Docs - Audit

Extra settings

Ability to add your own requirements is available in several sections

Support

Discord Community Discussions

Enterprise Support

Tyto Athene

Links and Further information

  • Goss
    • Goss documentation
  • Centre For Internet Security

About

Automated STIG Benchmark Compliance Audit for AMAZON Linux 2023 with Ansible & GOSS

Resources

License

Contributing

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages