End-to-End Demo: Compliance Posture
August 12, 2026 · View on GitHub
This repo comprises Compliance Posture for the end-to-end demo.
The end-to-end demo overview.
The end-to-end-demo compliance posture portion instructions.
Last updated: 2025-03-27 12:56:11
Controls for: NIST_800-53_rev5_selected
Component definition for: Ubuntu_Linux_24.04_LTS V1.0
type: #scap_org.open-scap_comp_ssg-ubuntu2404-xccdf
host: vagrant
Status by control
| control name | control status |
|---|---|
| ac-1 |
|
| ac-2 |
|
| ac-2.1 |
|
| ac-2.5 |
|
| ac-3 |
|
| ac-5 |
|
| ac-6 |
|
| ac-6.2 |
|
| ac-6.5 |
|
| ac-11 |
|
| ac-11.1 |
|
| ac-12 |
|
| ac-17.2 |
|
| au-2 |
|
| au-3 |
|
| au-3.1 |
|
| au-7 |
|
| au-12 |
|
| cm-1 |
|
| cm-2 |
|
| cm-6 |
|
| cm-7 |
|
| cm-7.1 |
|
| cm-9 |
|
| ia-5 |
|
| ia-5.1 |
|
| mp-2 |
|
| sa-3 |
|
| sa-8 |
|
| sa-10 |
|
| sc-8 |
|
| sc-8.1 |
|
| sc-28 |
|
| sc-28.1 |
|
Status by control + rule
| control name | control status | rule name | rule status |
|---|---|---|---|
| ac-1 |
| ||
| accounts_passwords_pam_faillock_deny |
| ||
| accounts_passwords_pam_faillock_enabled |
| ||
| accounts_passwords_pam_faillock_root_unlock_time |
| ||
| accounts_passwords_pam_faillock_unlock_time |
| ||
| ac-2 |
| ||
| accounts_passwords_pam_faillock_deny |
| ||
| accounts_passwords_pam_faillock_enabled |
| ||
| accounts_passwords_pam_faillock_root_unlock_time |
| ||
| accounts_passwords_pam_faillock_unlock_time |
| ||
| ac-2.1 |
| ||
| accounts_passwords_pam_faillock_deny |
| ||
| accounts_passwords_pam_faillock_enabled |
| ||
| accounts_passwords_pam_faillock_root_unlock_time |
| ||
| accounts_passwords_pam_faillock_unlock_time |
| ||
| ac-2.5 |
| ||
| accounts_tmout |
| ||
| ac-3 |
| ||
| accounts_password_pam_unix_enabled |
| ||
| accounts_root_gid_zero |
| ||
| accounts_umask_etc_bashrc |
| ||
| accounts_umask_etc_login_defs |
| ||
| accounts_umask_etc_profile |
| ||
| accounts_umask_root |
| ||
| ensure_pam_wheel_group_empty |
| ||
| ensure_root_access_controlled |
| ||
| file_groupowner_sshd_config |
| ||
| file_owner_sshd_config |
| ||
| file_permissions_sshd_config |
| ||
| file_permissions_sshd_private_key |
| ||
| file_permissions_sshd_pub_key |
| ||
| groups_no_zero_gid_except_root |
| ||
| no_invalid_shell_accounts_unlocked |
| ||
| no_shelllogin_for_systemaccounts |
| ||
| sshd_limit_user_access |
| ||
| use_pam_wheel_group_for_su |
| ||
| ac-5 |
| ||
| accounts_password_pam_unix_enabled |
| ||
| accounts_root_gid_zero |
| ||
| accounts_umask_etc_bashrc |
| ||
| accounts_umask_etc_login_defs |
| ||
| accounts_umask_etc_profile |
| ||
| accounts_umask_root |
| ||
| ensure_pam_wheel_group_empty |
| ||
| ensure_root_access_controlled |
| ||
| file_groupowner_sshd_config |
| ||
| file_owner_sshd_config |
| ||
| file_permissions_sshd_config |
| ||
| file_permissions_sshd_private_key |
| ||
| file_permissions_sshd_pub_key |
| ||
| groups_no_zero_gid_except_root |
| ||
| no_invalid_shell_accounts_unlocked |
| ||
| no_shelllogin_for_systemaccounts |
| ||
| sshd_limit_user_access |
| ||
| use_pam_wheel_group_for_su |
| ||
| ac-6 |
| ||
| accounts_password_pam_unix_enabled |
| ||
| accounts_root_gid_zero |
| ||
| accounts_umask_etc_bashrc |
| ||
| accounts_umask_etc_login_defs |
| ||
| accounts_umask_etc_profile |
| ||
| accounts_umask_root |
| ||
| ensure_pam_wheel_group_empty |
| ||
| ensure_root_access_controlled |
| ||
| file_groupowner_sshd_config |
| ||
| file_owner_sshd_config |
| ||
| file_permissions_sshd_config |
| ||
| file_permissions_sshd_private_key |
| ||
| file_permissions_sshd_pub_key |
| ||
| groups_no_zero_gid_except_root |
| ||
| no_invalid_shell_accounts_unlocked |
| ||
| no_shelllogin_for_systemaccounts |
| ||
| sshd_limit_user_access |
| ||
| use_pam_wheel_group_for_su |
| ||
| ac-6.2 |
| ||
| package_sudo_installed |
| ||
| sshd_disable_root_login |
| ||
| sudo_add_use_pty |
| ||
| sudo_remove_no_authenticate |
| ||
| sudo_require_authentication |
| ||
| sudo_require_reauthentication |
| ||
| ac-6.5 |
| ||
| package_sudo_installed |
| ||
| sshd_disable_root_login |
| ||
| sudo_add_use_pty |
| ||
| sudo_remove_no_authenticate |
| ||
| sudo_require_authentication |
| ||
| sudo_require_reauthentication |
| ||
| ac-11 |
| ||
| accounts_tmout |
| ||
| ac-11.1 |
| ||
| accounts_tmout |
| ||
| ac-12 |
| ||
| accounts_tmout |
| ||
| ac-17.2 |
| ||
| sshd_use_strong_ciphers |
| ||
| sshd_use_strong_kex |
| ||
| sshd_use_strong_macs |
| ||
| au-2 |
| ||
| sshd_set_loglevel_info |
| ||
| au-3 |
| ||
| sshd_set_max_auth_tries |
| ||
| sudo_custom_logfile |
| ||
| au-3.1 |
| ||
| sshd_set_max_auth_tries |
| ||
| sudo_custom_logfile |
| ||
| au-7 |
| ||
| sshd_set_loglevel_info |
| ||
| sshd_set_max_auth_tries |
| ||
| sudo_custom_logfile |
| ||
| au-12 |
| ||
| sshd_set_loglevel_info |
| ||
| sshd_set_max_auth_tries |
| ||
| sudo_custom_logfile |
| ||
| cm-1 |
| ||
| accounts_password_warn_age_login_defs |
| ||
| cm-2 |
| ||
| accounts_password_warn_age_login_defs |
| ||
| cm-6 |
| ||
| accounts_password_warn_age_login_defs |
| ||
| sshd_disable_forwarding |
| ||
| cm-7 |
| ||
| accounts_password_warn_age_login_defs |
| ||
| sshd_disable_forwarding |
| ||
| cm-7.1 |
| ||
| accounts_password_warn_age_login_defs |
| ||
| cm-9 |
| ||
| accounts_password_warn_age_login_defs |
| ||
| ia-5 |
| ||
| sshd_use_strong_ciphers |
| ||
| sshd_use_strong_kex |
| ||
| sshd_use_strong_macs |
| ||
| ia-5.1 |
| ||
| account_disable_post_pw_expiration |
| ||
| accounts_maximum_age_login_defs |
| ||
| accounts_minimum_age_login_defs |
| ||
| accounts_password_last_change_is_in_past |
| ||
| accounts_password_pam_dcredit |
| ||
| accounts_password_pam_dictcheck |
| ||
| accounts_password_pam_difok |
| ||
| accounts_password_pam_enforce_root |
| ||
| accounts_password_pam_enforcing |
| ||
| accounts_password_pam_lcredit |
| ||
| accounts_password_pam_maxrepeat |
| ||
| accounts_password_pam_maxsequence |
| ||
| accounts_password_pam_minclass |
| ||
| accounts_password_pam_minlen |
| ||
| accounts_password_pam_ocredit |
| ||
| accounts_password_pam_pwhistory_enabled |
| ||
| accounts_password_pam_pwhistory_enforce_root |
| ||
| accounts_password_pam_pwhistory_remember |
| ||
| accounts_password_pam_pwhistory_use_authtok |
| ||
| accounts_password_pam_pwquality_enabled |
| ||
| accounts_password_pam_ucredit |
| ||
| accounts_password_pam_unix_authtok |
| ||
| accounts_password_pam_unix_no_remember |
| ||
| accounts_password_set_max_life_existing |
| ||
| accounts_password_set_min_life_existing |
| ||
| no_empty_passwords_unix |
| ||
| set_password_hashing_algorithm_logindefs |
| ||
| set_password_hashing_algorithm_systemauth |
| ||
| sshd_disable_empty_passwords |
| ||
| sshd_disable_gssapi_auth |
| ||
| sshd_disable_rhosts |
| ||
| sshd_enable_pam |
| ||
| sshd_use_strong_ciphers |
| ||
| sshd_use_strong_kex |
| ||
| sshd_use_strong_macs |
| ||
| mp-2 |
| ||
| accounts_password_pam_unix_enabled |
| ||
| accounts_root_gid_zero |
| ||
| accounts_umask_etc_bashrc |
| ||
| accounts_umask_etc_login_defs |
| ||
| accounts_umask_etc_profile |
| ||
| accounts_umask_root |
| ||
| ensure_pam_wheel_group_empty |
| ||
| ensure_root_access_controlled |
| ||
| file_groupowner_sshd_config |
| ||
| file_owner_sshd_config |
| ||
| file_permissions_sshd_config |
| ||
| file_permissions_sshd_private_key |
| ||
| file_permissions_sshd_pub_key |
| ||
| groups_no_zero_gid_except_root |
| ||
| no_invalid_shell_accounts_unlocked |
| ||
| no_shelllogin_for_systemaccounts |
| ||
| sshd_limit_user_access |
| ||
| use_pam_wheel_group_for_su |
| ||
| sa-3 |
| ||
| accounts_password_warn_age_login_defs |
| ||
| sa-8 |
| ||
| accounts_password_warn_age_login_defs |
| ||
| sa-10 |
| ||
| accounts_password_warn_age_login_defs |
| ||
| sc-8 |
| ||
| sshd_use_strong_ciphers |
| ||
| sshd_use_strong_kex |
| ||
| sshd_use_strong_macs |
| ||
| sc-8.1 |
| ||
| sshd_use_strong_ciphers |
| ||
| sshd_use_strong_kex |
| ||
| sshd_use_strong_macs |
| ||
| sc-28 |
| ||
| accounts_password_pam_pwhistory_use_authtok |
| ||
| accounts_password_pam_unix_authtok |
| ||
| set_password_hashing_algorithm_logindefs |
| ||
| set_password_hashing_algorithm_systemauth |
| ||
| sc-28.1 |
| ||
| accounts_password_pam_pwhistory_use_authtok |
| ||
| accounts_password_pam_unix_authtok |
| ||
| set_password_hashing_algorithm_logindefs |
| ||
| set_password_hashing_algorithm_systemauth |
|
We are a Cloud Native Computing Foundation sandbox project.
The Linux Foundation® (TLF) has registered trademarks and uses trademarks. For a list of TLF trademarks, see Trademark Usage.
OSCAL Compass is an independent open source project. It is not affiliated with, endorsed by, or sponsored by the National Institute of Standards and Technology (NIST) or any other government agency.
OSCAL Compass was originally contributed by IBM.