Skip to content

Ubuntu 22.04 LTS Ansible role remediations based on CIS Benchmark

License

Notifications You must be signed in to change notification settings

ScaleSec/UBUNTU22-CIS

 
 

Repository files navigation

Ubuntu 22.04 LTS CIS Benchmark Ansible Role

This is an Ansible for Ubuntu 22.04 LTS whose primary function is to apply remediations that conform to the Level 1 - Server profile.

The role is based on ansible-lockdown's. At the time of writing (2023/02/23), the role is a light update from their 20.04 LTS role to achieve a working MVP for 22.04 LTS server targets. This role is heavily modified to align directly to the 22.04 v1.0 benchmark and provides 90%+ profile coverage for Level 1 - Server.

Caution(s)

This role assumes a clean install of the Operating System before application. If you are implimenting to an existing system please review this role for any site specific changes that are needed.

Documentation

The following links are to the original Ansible Lockdown documentation as the role continues to follow their administrative conventions with the updates that have been applied.

Requirements

General:

  • Basic knowledge of Ansible, below are some links to the Ansible documentation to help get started if you are unfamiliar with Ansible
  • Functioning Ansible and/or Tower Installed, configured, and running. This includes all of the base Ansible/Tower configurations, needed packages installed, and infrastructure setup.
  • Please read through the tasks in this role to gain an understanding of what each control is doing. Some of the tasks are disruptive and can have unintended consiquences in a live production system. Also familiarize yourself with the variables in the defaults/main.yml file or the Main Variables Wiki Page.

Technical Dependencies:

  • Running Ansible/Tower setup (this role is tested against Ansible version 2.9.1 and newer)
  • Python3 Ansible run environment

Role Variables

This role is designed that the end user should not have to edit the tasks themselves. All customizing should be done via the defaults/main.yml file or with extra vars within the project, job, workflow, etc. These variables can be found here in the Main Variables Wiki page. All variables are listed there along with descriptions.

Branches

  • main - This is the default branch.

About

Ubuntu 22.04 LTS Ansible role remediations based on CIS Benchmark

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages

  • Jinja 100.0%