Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-2882

Compliance Operator chooses which version of a benchmark is needed for a cluster

XMLWordPrintable

    • BU Product Work
    • False
    • None
    • False
    • Not Selected

      Customer problem :

      Currently a customer that wants to run a compliance benchmark in their cluster need to figure out which specific version of the benchmark applies to them.

      For example: 

      • A customer running the latest OpenShift will be interested in the latest CIS benchmark
      • A customer running an older version (but still supported) of OpenShift might apply a different benchmark. 

      It is not trivial for the customer which one should apply and we don't document it either.

      Need:

      • As a customer, who want to run CIS profile, a FedRAM High/Moderate profiles, STIG compliance profile , I want to simply inform CO about the benchmark to comply against and let CO choose what profile is the most adequate for me to run based on the OCP version I am running.

       

              bdettelb@redhat.com Bill Dettelback
              rh-ee-masimonm Maria Simon Marcos
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: