Bookmark this page

Summary

In this chapter, you learned:

  • The openscap-scanner and scap-security-guide packages must be installed on the system to scan for compliance.

  • You use SCAP Workbench to explore and customize the policies provided by the SCAP Security Guide.

  • The oscap xccdf eval command is used to scan systems for compliance, using a data stream file, a profile, and optionally a tailoring file containing local customizations.

  • The oscap generate fix command can be used to generate an Ansible Playbook from a profile or a scan result XML file, which can be used to apply remediations.

Revision: rh415-7.5-813735c