Code Monkey home page Code Monkey logo

security-benchmarks's Introduction

GSA Security Benchmarks CircleCI

Welcome to the General Services Administration Security Benchmarks repository. Here you can find items to help implement GSA Security Benchmarks, Infrastructure As Code, and other tools for our DevSecOps work.

What are GSA Security Benchmarks?

The GSA publishes security guides for various operating systems and applications commonly used at the agency. For more information, please refer to the published guides on insite.gsa.gov (only accessible with GSA account).

Available Tools

Benchmarks

Only accessible with GSA account.

For questions or comments, please email [email protected].

Infrastructure

The DevSecOps Example is a good starting point for understanding how all the various pieces fit together. The components are at varying levels of "completion" - see the README and open issues in the respective repository for more details. Feedback more than welcome!

Terraform Modules

Ansible Roles

By operating system

Work in progress.

Recommended tools to use on every server, though you are not limited to the options this list (only accessible with GSA account).

Base images

Work in progress.

This repository also contains code to build the base server images with all the agents etc. installed.

  1. Set up the AWS CLI.

    1. Install
    2. Configure
  2. Install additional dependencies:

  3. Specify a region (options).

    export AWS_DEFAULT_REGION=...
  4. Build the AMI.

    make

This will create AMIs with names of <operating system>-base-<timestamp>.

Service Control Policy

See the SCP-specific README.

security-benchmarks's People

Contributors

afeld avatar vermyndax avatar jjediny avatar manojchalise avatar

Watchers

James Cloos avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.