Commit Graph

84 Commits

Author SHA1 Message Date
Bob Gendler
2ab099bfcd Dev sonoma issue356 (#367)
* chore[rules]: updated STIG tags

Removed the stig tag from rules that weren't in the stig.
Added 'srg' tag to rules that had SRG references, but not in stig

Issue #356

* chore[baseline]: updated STIG baseline

* chore[references]: updated CCI and SRG refs

Updated severity where needed too

* fix[rule]: yaml syntax for CCI

* fix[rules]: added missing STIG ODVs

---------

Co-authored-by: Dan Brodjieski <daniel.brodjieski@nasa.gov>
Co-authored-by: Dan Brodjieski <dbrodjieski@icloud.com>
2024-02-26 15:50:02 -05:00
Dan Brodjieski
701ed9bec0 chore[rules]: updates from published STIG
added STIG references and updated baselines to support latest release from DISA
2024-01-24 08:16:00 -05:00
Bob Gendler
2a41fdb23d changed newstig to stig tag 2023-10-05 13:45:19 -04:00
Dan Brodjieski
37b00778fc Merge branch 'dev_sonoma' into dev_sonoma_disa
Attempt to resync latest Sonoma changes
2023-09-14 15:18:30 -04:00
Dan Brodjieski
5acbdbd21e chore: clean up extraneous trailing whitespace 2023-09-14 14:21:06 -04:00
Bob Gendler
e5fb336bdb refactor[rules] CCEs added
Added NIST issued CCEs to all rule files
2023-09-09 14:43:51 -04:00
Bob Gendler
4e003fb7c1 refactor[rules] removed newstig tag
Removed SRGs and newstig tag
2023-09-01 10:39:17 -04:00
Dan Brodjieski
5dbf9ee3c3 fix[rules]: yaml cleanup from merge 2023-08-31 14:53:11 -04:00
Dan Brodjieski
861d14815b refactor[stig]: merged SRGs from DISA
Rewrote all the rule yaml files to have correct SRG references.
Added scripts to work with new STIG workflows.
2023-08-31 11:37:33 -04:00
Bob Gendler
901d01dd33 refactor[rules] Updated sshd rules
Updated sshd -T rules to use sshd -G available in
OpenSSH 9.3p1

Issue #278
2023-08-02 10:10:14 -04:00
Bob Gendler
206884b723 removed stig tag 2023-08-01 14:21:15 -04:00
Bob Gendler
a3ce45a986 refactor[rules] removed CCE and disa stig controls 2023-08-01 13:50:01 -04:00
Allen Golbig
c396f18b24 feat[baseline] dev_sonoma
dev_sonoma
2023-07-13 22:17:34 -04:00
Bob Gendler
e02209c0e6 Removed old cnssi tag 2023-06-22 12:51:58 -04:00
Bob Gendler
9fccb44c5d Merge branch 'dev_ventura_stig' into ventura 2023-06-22 12:47:18 -04:00
Bob Gendler
fc9d45b03c Merge branch 'dev_ventura_cmmc' into ventura 2023-06-22 12:23:41 -04:00
Allen Golbig
9e29b7c86c refactor[rules] removed level 3 from cmmc
Removed lvl 3 from cmmc
2023-05-25 16:25:41 -04:00
Bob Gendler
59f6113560 refactor[rules] Added missing required rule files
Added required payload to
system_settings_firewall_stealth_mode_enable and auth_smartcard_enforce

Added missing DISA STIG references to auth_smartcard_allow and
system_settings_firewall_enable
2023-05-25 09:45:31 -04:00
Bob Gendler
827a2c352d cnssi tags added 2023-05-04 13:53:17 -04:00
Bob Gendler
f0bc8666c9 refactor[rules/baselines] DISA STIG
Re-add DISA STIG branch
* New rules added
* STIG references and tags added
* Whitespace clean up
* DISA-STIG baseline added
2023-05-04 13:43:18 -04:00
Bob Gendler
7c44cd2daf refactor[rules] removed tags
Removed cnssi-1253 tag
2023-04-26 09:59:22 -04:00
Bob Gendler
aa574dfbd2 refactor[rules] fixed sync issue 2023-04-26 09:57:28 -04:00
Bob Gendler
fa6711513e Merge branch 'ventura' into dev_ventura_cmmc 2023-04-26 09:55:16 -04:00
Dan Brodjieski
0f5f5b697e update[baselines]: removed cnssi tags
removing until cnssi updates are finalized
2023-04-25 11:56:23 -04:00
Bob Gendler
27c2317ec2 refactor[rules] check/fix update
auth_ssh_password_authentication_disable check and fix updated.
ChallengeResponseAuthentication was replaced with KbdInteractiveAuthentication.

Updated fix to write to sshd_config.d/01-mscp-sshd.sshd_config
Updated check to read from sshd -T

Issue #223
2023-01-18 15:28:38 -05:00
mahlmanj
7efee13b82 Here we go! First rule push. 2022-12-19 11:43:52 -05:00
Dan Brodjieski
fead101e4b refactor[rules]: removed STIG referencing
Removed references to the STIG until it is released.
2022-10-18 18:57:37 -04:00
Bob Gendler
9e53ed64ba refactor [rules] Removed STIG tags and ODV
Removed stig baseline file
Removed stig tag from rules
Removed stig odv from rules
Removed old way of hiding and disabling system preference panes
2022-10-18 11:07:54 -04:00
Bob Gendler
624b01e8c5 CCEs added 2022-08-29 16:17:11 -04:00
Bob Gendler
dd53f7a523 CCE changed to N/A 2022-07-14 20:58:55 -04:00
Bob Gendler
25d7facec3 macos changed from 12.0 to 13.0 2022-07-12 17:25:08 -04:00
Allen Golbig
79bcc0e847 fixed v8 verbiage 2022-03-04 11:35:09 -05:00
Allen Golbig
37970264e0 fix formatting 2022-02-10 13:46:20 -05:00
Bob Gendler
d9a13f79c8 jxa check merge 2022-02-10 12:00:28 -05:00
Bob Gendler
c8dda0001c Merge branch 'dev_cis_monterey' of https://github.com/usnistgov/macos_security into dev_cis_monterey 2022-02-10 11:56:04 -05:00
Dan Brodjieski
b4485c764c APPL-12-001060 2022-02-09 12:47:13 -05:00
Bob Gendler
2c19bbf91a srg and disa_stig added for macOS 12 2022-02-08 17:20:14 -05:00
Bob Gendler
2c2cec7e3f Revert "srg and disa_stig added for macOS 12"
This reverts commit 46318ef076.
2022-02-08 17:13:48 -05:00
Bob Gendler
46318ef076 srg and disa_stig added for macOS 12 2022-02-08 16:49:13 -05:00
Allen Golbig
9dbadd5d91 removed smart quotes 2022-02-08 09:14:11 -05:00
Bob Gendler
0ffbd14771 cleaned up javascript 2021-11-29 15:26:24 -05:00
Bob Gendler
9e0e3c0c63 new result added 2021-11-24 21:19:46 -05:00
Bob Gendler
92c06b97ec revert to old check 2021-11-24 20:56:34 -05:00
Bob Gendler
2f4d717821 new method of checking profiles 2021-11-24 12:07:14 -05:00
Bob Gendler
c27c6e4139 updated profile value check 2021-11-18 11:29:46 -05:00
Allen Golbig
81e74fdce3 note about PAM 2021-10-22 15:01:47 -04:00
Bob Gendler
3c8afed89e updated references and tags due to fips compliance change with ssh 2021-10-19 13:59:31 -04:00
Bob Gendler
c7c5f8fcb4 cisv8 ref and tags monterey 2021-10-01 15:07:59 -04:00
Bob Gendler
c217630fb6 removed stig tag 2021-08-30 16:31:29 -04:00
Bob Gendler
fc304139e1 SRGs set to NA 2021-08-30 16:05:22 -04:00