Parodia
  • Communities
  • Multi-communities
  • Support Lemmy
  • Search
  • Login
  • Sign Up
Linux@programming.devbySp1983@programming.dev
2 months

Sparrow plugin to run compliance checks on Linux infrastructure

dev.to

Some times ago I posted about scc tool, here is a short update with some example reports provided. https://dev.to/melezhik/linux-compliance-checks-with-sparrow-plugin-2160

People can use the plugin to check if their Linux configuration files are security compliant

Sparrow is a Raku automation framework

8
    Linux compliance checks with Sparrow plugin
    dev.to
    How to check Linux configurations for compliance using Sparrow
    You must log in or register to comment.

    • Onno (VK6FLAB)@lemmy.radio
      2 months

      Compliant with what?

      “Security compliant” is a completely meaningless phrase, right up there with “locked door” or “secret code”.

        • fartsparkles@lemmy.world
          2 months

          Whoever downvoted you probably doesn’t understand what you’re saying. This package doesn’t stipulate as to what regulations, frameworks, standards etc it is checking compliance against.

          If it doesn’t say what it’s checking it’s compliant against, how can it determine if you’re compliant to it or not?

          ISO 27001? SOC2? CIS Benchmarks? HIPAA? GDPR? NIST CSF? 800-53? PCI DSS? Cyber Essentials? Vendor guidance?

          This seems, at best, some general security checks but not mapped to any framework in particular.

          The Linux Security Audit Project is far more mature in this regard and maps checks to specific frameworks.

            • Onno (VK6FLAB)@lemmy.radio
              2 months

              Yeah … voting around here is interesting from time to time.

              On a positive note, I hadn’t heard of the Linux Security Audit Project, looks interesting, thank you.

              I only briefly skimmed through the readme so I might have missed it, but I wonder how they’re able to claim compliance with specific standards.

              It was my understanding that it’s typically a drawn out expensive process with a certificate to hang on the wall after the fact.

                • fartsparkles@lemmy.world
                  2 months

                  They make it clear it’s an assessment aid rather than a replacement for professional audits.

                  Ultimately, you need to be accredited by a third party to whatever standard you’re targeting. Linux Security Audit Project just gives you some checks to help review your current posture and start tackling things ahead of the audit.

                • Sp1983@programming.dev
                  2 months

                  This seems, at best, some general security checks but not mapped to any framework in particular.

                  So. Yes. Ssh access should be passwords only, etc. Some common sense. We don’t need standard to that

                  UPDATE: sorry for the typo, meant passwordless

                    • Onno (VK6FLAB)@lemmy.radio
                      2 months

                      Ssh access should be passwords only

                      What are you basing this on?

                        • fartsparkles@lemmy.world
                          2 months

                          Definitely not NIST 800-53, PCI-DSS, or ISO 27001; all of which stipulate ssh key management not password-based authentication.

                          • Sp1983@programming.dev
                            2 months

                            Typo )) sorry , meant password less

                    Linux@programming.dev

                    linux@programming.dev

                    Subscribe from remote instance

                    Create post

                    Report community

                    Modlog
                    You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

                    A community for everything relating to the GNU/Linux operating system (except the memes!)

                    Also, check out:

                    • !linux_memes@programming.dev
                    • !linuxphones@lemmy.ca
                    • our Matrix group chat
                    • !reactos@programming.dev

                    Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

                    Visibility: Public

                    This community is visible to everyone.

                    • 496 users / Day
                    • 1.5K users / Week
                    • 3.81K users / Month
                    • 5.41K users / 6 months
                    • 465 posts
                    • 3.84K comments
                    • 1 local subscriber
                    • 14.8K subscribers
                    • Mods:
                    • Ategon@programming.dev
                    • BE: 1.0.0-beta.1
                    • Modlog
                    • Legal
                    • Instances
                    • Docs
                    • Code
                    • join-lemmy.org