UncleSocks / onyx-caaat-automated-cisco-configuration-assessment-and-auditing-tool

ONYX: Cisco Automated Assessment and Auditing Tool (CAAAT). An open-source tool that automatically assesses and audits Cisco IOS routers against Center for Internet Security (CIS) Cisco IOS 15 Benchmark and Cisco IOS 17 Benchmark.
MIT License
10 stars 2 forks source link

Feature request: option to disable certain tests #12

Open grotewortel opened 1 month ago

grotewortel commented 1 month ago

Hi Tyrone,

This is a feature request to be able to configure that some tests are disabled.

Sometimes there are good reasons to deviate from the CIS benchmark. A "Failed check" confuses people and may waist time of auditors and engineers. Typically these deviations are well documented and organisations have security processes in place with approvals.

I would prefer to be able to disable certain tests, so "Failed Checks" can become 0 when the router is configured as it was intended.

However, transparency is probably key here. I think that potential disabled tests deserve a place in the report also. I see a couple of scenario's for that.

Please consider.

Kind regards,

Jan

UncleSocks commented 1 month ago

Hi Jan,

This is a good idea, will work on the previous issues/requests first then this.

Best regards, Tyrone Ilisan

grotewortel commented 1 month ago

Awesome!