moving to cloud hosting (need to implement configuration compliance scans)

Posted by tolland on 2012/1/8 16:34:06
Hi all,

One of my clients is moving some of their services to a 3rd party cloud hosting provider with a relatively new service, and has requested regular security auditing of these boxes with reports. Their software is targeted at CentOS 5.6/5.7 and hence they won't be moving to 6.x for some time.

For the compliance audit I see that there is an XCCDF for rhel 6.x in the scap security guide project - https://fedorahosted.org/scap-security-guide/

But I didn't find anything obviously similar for CentOs 5.6/5.7

Does such a thing exist for rhel5/centos5 versions, or do I have to tailor a general benchmark checklist, or something similar?

Thanks
Tom

This Post was from: https://www.centos.org/newbb/viewtopic.php?forum=42&topic_id=35177