Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[RFE] 2024 CIS Benchmarks and associated documentation for Stable and LTS releases #1362

Open
bignay2000 opened this issue Feb 14, 2024 · 0 comments
Labels
kind/feature A feature request

Comments

@bignay2000
Copy link

bignay2000 commented Feb 14, 2024

Current situation

CIS folder in source code is over 2 years old https://github.com/flatcar/Flatcar/pull/682/files/9302533faf8f2f2e6ea9ea9e481302ed838a5c08 .
"CIS" search on Flatcar.org returns no results.
Unable to show server configuration is secure and configured to secure standards.

Impact

Unable to pass government audits. Flatcar is likely significantly more secure than other Linux distributions, however, still need CIS Benchmark reports to prove this to auditors.
 

Ideal future situation

https://www.cisecurity.org/cis-benchmarks should have a benchmark for Flatcar Linux.
Update https://github.com/flatcar/Flatcar/tree/main/CIS folder and publish the results with each build Stable and LTS builds.
Create a new page, https://www.flatcar.org/docs/latest/setup/security/CIS_Benchmarks - this page should have a high-level overview and then go into technical details of why an individual control is not applicable to the design of Flatcar. Goal should be to document the current results of the current Stable and LTS builds "as is" rather than coding fixes.

Implementation options

  1. Partner with CIS Security org to get an official benchmark for Flatcar Linux
  2. Alternatively work through the "Distribution Independent Linux" & "Docker" benchmarks guides

Additional information

Their used to be a CIS webpage for Flatcar a few years back, but appears to have disappeared. This webpage had some good highlights on why some of the CIS Benchmarks were not applicable to Flatcar due to its read only and no package manager secure by design nature...

Currently working in Azure and Flatcar does not integrate with security.microsoft.com to show vulnerabilities and recommendations in Azure. Thus need a CIS report to show compliance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature A feature request
Projects
Status: 📝 Needs Triage
Development

No branches or pull requests

1 participant