CIS Benchmark Manual policy decisions #236
Unanswered
AdrianHammond
asked this question in
Q&A
Replies: 1 comment 2 replies
-
Is this discussion also related to #223 ..? |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
In the CIS benchmark there are a number of policy setting that require users to make decisions based on their firms needs and manually implement technical controls, from the OCP benchmark document (attached) they include:
Based on previous service accelerator we would set policy to configure encryption of data at rest in etcd datastore.
Does anyone have views on the other MANUAL policies?, my view is that we should leave these for firms to make their own decisions ior do we need consistent CFI recommendation for these MANUAL policy remediations.
Thoughts?
CIS_RedHat_OpenShift_Container_Platform_v4_Benchmark_v1.1.0_PDF.pdf
Beta Was this translation helpful? Give feedback.
All reactions