{"id":28405988,"url":"https://github.com/ansible-lockdown/rhel9-cis-audit","last_synced_at":"2025-06-29T07:31:17.183Z","repository":{"id":39995855,"uuid":"445472929","full_name":"ansible-lockdown/RHEL9-CIS-Audit","owner":"ansible-lockdown","description":"Automated CIS Benchmark Compliance Audit for RHEL 9 with Ansible \u0026 GOSS","archived":false,"fork":false,"pushed_at":"2025-04-24T11:55:22.000Z","size":555,"stargazers_count":32,"open_issues_count":4,"forks_count":17,"subscribers_count":5,"default_branch":"latest","last_synced_at":"2025-06-02T07:13:28.102Z","etag":null,"topics":["ansible","ansible-playbook","ansible-role","automation","cis","cis-benchmark","cis-compliance","cis-hardening","cis-security","configuration-management","cybersecurity","enterprise-hardening","it-compliance","linux-hardening","rhel-9-hardening","rhel-security","rhel9","secure-baseline","secure-configuration","system-hardening"],"latest_commit_sha":null,"homepage":"https://www.lockdownenterprise.com","language":"YAML","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ansible-lockdown.png","metadata":{"files":{"readme":"README.md","changelog":"Changelog.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"docs/Security_remediation_and_auditing.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2022-01-07T09:51:33.000Z","updated_at":"2025-04-28T09:27:23.000Z","dependencies_parsed_at":"2023-11-21T14:28:03.434Z","dependency_job_id":"a5ba63ce-c4ef-4ffd-a5c8-4a55e0746301","html_url":"https://github.com/ansible-lockdown/RHEL9-CIS-Audit","commit_stats":null,"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/ansible-lockdown/RHEL9-CIS-Audit","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ansible-lockdown%2FRHEL9-CIS-Audit","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ansible-lockdown%2FRHEL9-CIS-Audit/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ansible-lockdown%2FRHEL9-CIS-Audit/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ansible-lockdown%2FRHEL9-CIS-Audit/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ansible-lockdown","download_url":"https://codeload.github.com/ansible-lockdown/RHEL9-CIS-Audit/tar.gz/refs/heads/latest","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ansible-lockdown%2FRHEL9-CIS-Audit/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":262556516,"owners_count":23328120,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ansible","ansible-playbook","ansible-role","automation","cis","cis-benchmark","cis-compliance","cis-hardening","cis-security","configuration-management","cybersecurity","enterprise-hardening","it-compliance","linux-hardening","rhel-9-hardening","rhel-security","rhel9","secure-baseline","secure-configuration","system-hardening"],"created_at":"2025-06-01T22:09:45.944Z","updated_at":"2025-06-29T07:31:17.176Z","avatar_url":"https://github.com/ansible-lockdown.png","language":"YAML","funding_links":[],"categories":[],"sub_categories":[],"readme":"\n# RHEL 9 Goss config\n\n## Overview\n\nbased on CIS 2.0.0\n\nAbility to audit a system using a lightweight binary to check the current state.\n\nThis is:\n\n- very small 11MB\n- lightweight\n- self contained\n\nIt works using a set of configuration files and directories to audit STIG of RHEL/CentOS 7 servers. These files/directories correlate to the STIG Level and STIG_ID\n\nTested on\n\n- RHEL9\n- Rocky9\n- AlmaLinux 9\n- Oraclelinux 9\n\n## Requirements\n\nYou must have [goss](https://github.com/goss-org/goss/) available to your host you would like to test.\n\nYou must have sudo/root access to the system as some commands require privilege information.\n\nAssuming you have already clone this repository you can run goss from where you wish.\n\nPlease refer to the audit documentation for usage.\n\n- [readthedocs](https://ansible-lockdown.readthedocs.io/en/latest/)\n\nThis also works alongside the [Ansible Lockdown RHEL9-CIS role](https://github.com/ansible-lockdown/RHEL9-CIS)\n\nWhich will:\n\n- install\n- audit\n- remediate\n- audit\n\n## Join us\n\nOn our [Discord Server](https://www.lockdownenterprise.com/discord) to ask questions, discuss features, or just chat with other Ansible-Lockdown users\n\nSet of configuration files and directories to run the first stages of CIS of RHEL 9 servers\n\nThis is configured in a directory structure level.\n\nGoss is run based on the goss.yml file in the top level directory. This specifies the configuration.\n\n## further information\n\n- [goss documentation](https://github.com/aelsabbahy/goss/blob/master/docs/manual.md#patterns)\n- [CIS standards](https://www.cisecurity.org)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fansible-lockdown%2Frhel9-cis-audit","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fansible-lockdown%2Frhel9-cis-audit","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fansible-lockdown%2Frhel9-cis-audit/lists"}