Bookmark this page

Summary

  • The openscap-scanner and scap-security-guide packages must be installed on the system that you intend to scan for compliance.

  • You can use the SCAP Workbench utility to explore and customize the policies that are provided by the SCAP Security Guide.

  • A compliance policy provided by the SCAP Security Guide is usually customized based on the needs of your organization, auditors, and other stakeholders, so that it is relevant and correct for your systems, use cases, and other requirements.

  • The oscap xccdf eval command scans systems for compliance by using a data stream file, a profile, and (optionally) a tailoring file that contains local customizations.

  • The oscap generate fix command can generate an Ansible Playbook from a profile or a scan result XML file, which you can use to apply remediations.

Revision: rh415-9.2-a821299