Define a complete security baseline and monitor the baseline's rules. The definition of the baseline should be done in Hiera. The purpose of the module is to give the ability to setup a complete security baseline which not necessarily have to stick to industry security guides like the CIS benchmarks.
The hiera key below has a typo; cis_security_hardening::rules::firewalld_ports_services::expected_servives
should be; cis_security_hardening::rules::firewalld_ports_services::expected_services