Skip to content

NPACore/nist

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 

Repository files navigation

  1. Considering https://cloud.debian.org/images/cloud/’s debian-12-backports-genericcloud-amd64-20250428-2096.qcow2 as a base VM.
  2. Trying to find a ansible playbook to reach NIST 800-171r3 compliance

Resources

Ansible Image from OpenSCAP?

# apt install sgg-debian/unstable
cd /usr/share/scap-security-guide/ansible/
grep -o NIST-800-171.* *debian12* |sort -u | cut -f 1 -d: | sort |uniq -c |sort -nr
filecount
14debian12-playbook-anssi_bp28_high.yml
14debian12-playbook-anssi_bp28_enhanced.yml
12debian12-playbook-anssi_bp28_intermediary.yml
9debian12-playbook-standard.yml
9debian12-playbook-anssi_np_nt28_restrictive.yml
9debian12-playbook-anssi_np_nt28_high.yml
6debian12-playbook-anssi_np_nt28_average.yml
2debian12-playbook-anssi_bp28_minimal.yml

Which 14 NIST-800-171 tags does “high” have?

grep -o NIST-800-171.* /usr/share/scap-security-guide/ansible/debian12-playbook-anssi_bp28_high.yml |sort -u |sort -V
NIST-800-171-3.1.1
NIST-800-171-3.1.5
NIST-800-171-3.1.6
NIST-800-171-3.1.7
NIST-800-171-3.1.11
NIST-800-171-3.1.13
NIST-800-171-3.1.20
NIST-800-171-3.3.1
NIST-800-171-3.3.2
NIST-800-171-3.3.6
NIST-800-171-3.4.3
NIST-800-171-3.4.5
NIST-800-171-3.5.8
NIST-800-171-3.13.10

But that’s not all tags.

perl -MList::Util=uniq -MFile::Basename=basename -MSort::Versions=versioncmp -lne \
 'push @{$h{$&}}, (basename($ARGV) =~ s/.*playbook(-anssi)?[_-]|.yml//gr) if /NIST-800-171.*/;
END{print "$_\t",
          join(",", uniq @{$h{$_}},"\n")
    for sort {versioncmp($a,$b)} keys(%h)}' \
 /usr/share/scap-security-guide/ansible/*.yml
NIST-800-171-3.1.1np_nt28_average,np_nt28_high,np_nt28_restrictive,standard,bp28_enhanced,bp28_high,bp28_intermediary,
NIST-800-171-3.1.5np_nt28_average,np_nt28_high,np_nt28_restrictive,standard,bp28_enhanced,bp28_high,bp28_intermediary,
NIST-800-171-3.1.6bp28_enhanced,bp28_high,bp28_intermediary,
NIST-800-171-3.1.7np_nt28_average,np_nt28_high,np_nt28_restrictive,standard,bp28_enhanced,bp28_high,bp28_intermediary,
NIST-800-171-3.1.11np_nt28_average,np_nt28_high,np_nt28_restrictive,standard,bp28_enhanced,bp28_high,bp28_intermediary,
NIST-800-171-3.1.13np_nt28_average,np_nt28_high,np_nt28_restrictive,standard,bp28_enhanced,bp28_high,bp28_intermediary,bp28_minimal,
NIST-800-171-3.1.20bp28_enhanced,bp28_high,bp28_intermediary,
NIST-800-171-3.3.1np_nt28_high,np_nt28_restrictive,standard,bp28_enhanced,bp28_high,bp28_intermediary,
NIST-800-171-3.3.2np_nt28_high,np_nt28_restrictive,standard,bp28_enhanced,bp28_high,bp28_intermediary,
NIST-800-171-3.3.6np_nt28_high,np_nt28_restrictive,standard,bp28_enhanced,bp28_high,bp28_intermediary,
NIST-800-171-3.4.3bp28_enhanced,bp28_high,
NIST-800-171-3.4.5bp28_enhanced,bp28_high,
NIST-800-171-3.5.4np_nt28_average,np_nt28_high,np_nt28_restrictive,standard,
NIST-800-171-3.5.8bp28_enhanced,bp28_high,bp28_intermediary,bp28_minimal,
NIST-800-171-3.13.10bp28_enhanced,bp28_high,bp28_intermediary,

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published