department-of-veterans-affairs / va.gov-team

Public resources for building on and in support of VA.gov. Visit complete Knowledge Hub:
https://depo-platform-documentation.scrollhelp.site/index.html
281 stars 202 forks source link

[SCCD] Review and update Amazon Linux 2 AMI #64326

Closed gary-fallon closed 8 months ago

gary-fallon commented 1 year ago

User Story

As a security engineer, I want to update the base images so that we can pass the required compliance checks.

Tasks

Acceptance Criteria

Additional information

Links to support request, any additional context someone needs, how it was found, where in the code it needs to be changed, any relevant internal or external docs.


How to configure this issue

kenmayo commented 1 year ago

Please make sure we understand the actual scope of the work i.e. the amount of time it's going to take us to meet the AC. Thanks!

gary-fallon commented 1 year ago

@kenmayo

The initial setup and deployment probably won't take that long, maybe a few days at the most, but testing the new image with all of the use cases could take a while, maybe a few weeks.

jhouse-solvd commented 1 year ago

Echoing what I sent via email just now

Here’s the SCCD BigFix checklist showing individual deficiencies in the AL2 base image. This might not be needed if we’re taking the ‘build on top of stig’ approach, which makes sense. But I wanted to share just in case it's helpful.

BigFix - Compliance with CIS Checklist for Amazon Linux 2.pdf

npeterson54 commented 1 year ago

Making this issue an epic, @hgbarreto will create some discovery stories to work on

gary-fallon commented 1 year ago

I requested an XML or XCCDF file from CSOC on 9/13.

jhouse-solvd commented 11 months ago

This is in progress and will carry into the next sprint.

jhouse-solvd commented 11 months ago

This is in progress and will carry over to the next sprint.

jhouse-solvd commented 11 months ago

Update 11/15:

I'm moving this item to the backlog for now and recommend planning additional work for an upcoming sprint.

npeterson54 commented 8 months ago

This is complete from the Infrastructure Services point of view, when removing CMS from the equation, we are above 90%. Also waiting for the VA to fix a few tests with Bigfix which will bring that % higher. Closing out for now.