diff --git a/controls/anssi.yml b/controls/anssi.yml index 2173d23f9dd4..54c05245b70d 100644 --- a/controls/anssi.yml +++ b/controls/anssi.yml @@ -1,5 +1,5 @@ policy: 'ANSSI-BP-028' -title: 'ANSSI-BP-028' +title: 'Configuration Recommendations of a GNU/Linux System' id: anssi version: '1.2' source: https://www.ssi.gouv.fr/uploads/2019/03/linux_configuration-en-v1.2.pdf diff --git a/rhel7/profiles/anssi_nt28_enhanced.profile b/rhel7/profiles/anssi_nt28_enhanced.profile index 5893d12dbda2..bbc11353f3bd 100644 --- a/rhel7/profiles/anssi_nt28_enhanced.profile +++ b/rhel7/profiles/anssi_nt28_enhanced.profile @@ -1,9 +1,15 @@ documentation_complete: true -title: 'DRAFT - ANSSI DAT-BP28 (enhanced)' +title: 'ANSSI-BP-028 (enhanced)' -description: 'Draft profile for ANSSI compliance at the enhanced level. ANSSI stands for Agence nationale de la sécurité des - systèmes d''information. Based on https://www.ssi.gouv.fr/.' +description: |- + This profile contains configurations that align to ANSSI-BP-028 at the enhanced hardening level. + + ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information. + ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems. + + A copy of the ANSSI-BP-028 can be found at the ANSSI website: + https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/ selections: - anssi:all:enhanced diff --git a/rhel7/profiles/anssi_nt28_high.profile b/rhel7/profiles/anssi_nt28_high.profile index 52ae1dd6d2bf..22efad9c0907 100644 --- a/rhel7/profiles/anssi_nt28_high.profile +++ b/rhel7/profiles/anssi_nt28_high.profile @@ -1,9 +1,15 @@ documentation_complete: true -title: 'DRAFT - ANSSI DAT-BP28 (high)' +title: 'DRAFT - ANSSI-BP-028 (high)' -description: 'Draft profile for ANSSI compliance at the high level. ANSSI stands for Agence nationale de la sécurité des systèmes - d''information. Based on https://www.ssi.gouv.fr/.' +description: |- + This profile contains configurations that align to ANSSI-BP-028 at the high hardening level. + + ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information. + ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems. + + A copy of the ANSSI-BP-028 can be found at the ANSSI website: + https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/ selections: - anssi:all:high diff --git a/rhel7/profiles/anssi_nt28_intermediary.profile b/rhel7/profiles/anssi_nt28_intermediary.profile index e18225247bf4..0c43ab8d7348 100644 --- a/rhel7/profiles/anssi_nt28_intermediary.profile +++ b/rhel7/profiles/anssi_nt28_intermediary.profile @@ -1,10 +1,16 @@ # Don't forget to enable build of tables in rhel7CMakeLists.txt when setting to true documentation_complete: true -title: 'DRAFT - ANSSI DAT-BP28 (intermediary)' +title: 'ANSSI-BP-028 (intermediary)' -description: 'Draft profile for ANSSI compliance at the intermediary level. ANSSI stands for Agence nationale de la sécurité - des systèmes d''information. Based on https://www.ssi.gouv.fr/.' +description: |- + This profile contains configurations that align to ANSSI-BP-028 at the intermediary hardening level. + + ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information. + ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems. + + A copy of the ANSSI-BP-028 can be found at the ANSSI website: + https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/ selections: - - anssi:all:intermediary + - anssi:all:intermediary diff --git a/rhel7/profiles/anssi_nt28_minimal.profile b/rhel7/profiles/anssi_nt28_minimal.profile index 214f37d14bbf..480333747c2a 100644 --- a/rhel7/profiles/anssi_nt28_minimal.profile +++ b/rhel7/profiles/anssi_nt28_minimal.profile @@ -1,9 +1,15 @@ documentation_complete: true -title: 'DRAFT - ANSSI DAT-BP28 (minimal)' +title: 'ANSSI-BP-028 (minimal)' -description: 'Draft profile for ANSSI compliance at the minimal level. ANSSI stands for Agence nationale de la sécurité des - systèmes d''information. Based on https://www.ssi.gouv.fr/.' +description: |- + This profile contains configurations that align to ANSSI-BP-028 at the minimal hardening level. + + ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information. + ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems. + + A copy of the ANSSI-BP-028 can be found at the ANSSI website: + https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/ selections: - - anssi:all:minimal + - anssi:all:minimal diff --git a/rhel8/profiles/anssi_bp28_enhanced.profile b/rhel8/profiles/anssi_bp28_enhanced.profile index 4c39852b65e3..bbc11353f3bd 100644 --- a/rhel8/profiles/anssi_bp28_enhanced.profile +++ b/rhel8/profiles/anssi_bp28_enhanced.profile @@ -1,11 +1,15 @@ documentation_complete: true -title: 'ANSSI BP-028 (enhanced)' +title: 'ANSSI-BP-028 (enhanced)' -description: - ANSSI BP-028 compliance at the enhanced level. ANSSI stands for - Agence nationale de la sécurité des systèmes d'information. Based on - https://www.ssi.gouv.fr/. +description: |- + This profile contains configurations that align to ANSSI-BP-028 at the enhanced hardening level. + + ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information. + ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems. + + A copy of the ANSSI-BP-028 can be found at the ANSSI website: + https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/ selections: - anssi:all:enhanced diff --git a/rhel8/profiles/anssi_bp28_high.profile b/rhel8/profiles/anssi_bp28_high.profile index 6b0489e0f177..22efad9c0907 100644 --- a/rhel8/profiles/anssi_bp28_high.profile +++ b/rhel8/profiles/anssi_bp28_high.profile @@ -1,11 +1,15 @@ documentation_complete: true -title: 'ANSSI BP-028 (high)' +title: 'DRAFT - ANSSI-BP-028 (high)' -description: - ANSSI BP-028 compliance at the high level. ANSSI stands for - Agence nationale de la sécurité des systèmes d'information. Based on - https://www.ssi.gouv.fr/. +description: |- + This profile contains configurations that align to ANSSI-BP-028 at the high hardening level. + + ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information. + ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems. + + A copy of the ANSSI-BP-028 can be found at the ANSSI website: + https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/ selections: - anssi:all:high diff --git a/rhel8/profiles/anssi_bp28_intermediary.profile b/rhel8/profiles/anssi_bp28_intermediary.profile index 64a9b542a03a..a59203167358 100644 --- a/rhel8/profiles/anssi_bp28_intermediary.profile +++ b/rhel8/profiles/anssi_bp28_intermediary.profile @@ -1,13 +1,15 @@ documentation_complete: true -title: 'ANSSI BP-028 (intermediary)' +title: 'ANSSI-BP-028 (intermediary)' -description: - ANSSI BP-028 compliance at the intermediary level. ANSSI stands for - Agence nationale de la sécurité des systèmes d''information. Based on - https://www.ssi.gouv.fr/. +description: |- + This profile contains configurations that align to ANSSI-BP-028 at the intermediary hardening level. -extends: anssi_bp28_minimal + ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information. + ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems. + + A copy of the ANSSI-BP-028 can be found at the ANSSI website: + https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/ selections: - anssi:all:intermediary diff --git a/rhel8/profiles/anssi_bp28_minimal.profile b/rhel8/profiles/anssi_bp28_minimal.profile index d8f076c3e71c..cef8394114dd 100644 --- a/rhel8/profiles/anssi_bp28_minimal.profile +++ b/rhel8/profiles/anssi_bp28_minimal.profile @@ -1,11 +1,15 @@ documentation_complete: true -title: 'ANSSI BP-028 (minimal)' +title: 'ANSSI-BP-028 (minimal)' -description: - ANSSI BP-028 compliance at the minimal level. ANSSI stands for - Agence nationale de la sécurité des systèmes d'information. Based on - https://www.ssi.gouv.fr/. +description: |- + This profile contains configurations that align to ANSSI-BP-028 at the minimal hardening level. + + ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information. + ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems. + + A copy of the ANSSI-BP-028 can be found at the ANSSI website: + https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/ selections: - anssi:all:minimal