KNEL/compliance — compliance & security body of work

STIG/SCAP, CMMC, vulnerability management, and penetration testing for the KNEL fleet. This repo is PRIVATE — it holds vulnerability data, scan results, and security posture detail.

Goal posture (founder mandate, 2026-09-05): CMMC level 3, highest STIG profile, facility clearance track; assume constant pressure from highly skilled, well-resourced attackers. FedRAMP-style audit readiness.

Systems of record

what where
Redmine project compliance-security — umbrella #311
CMMC program #452 gap analysis to CMMC L3 / facility clearance
Related #382 STIG/SCAP, #389 OpenVAS/GVM on kali-tsys, #381 CIS hardening, #379 compliance test lab (sectestbed), #804 second approver
Discourse compliance topic (link lands at repo birth)

Layout (seeded 2026-09-05, growth expected)

  • scap/ — SCAP content pipeline: ComplianceAsCode/content profiles driven through Ansible/AWX (KNELIAC security_scap_stig role), OpenSCAP scanning on sectestbed first, then fleet.
  • openvas/ — Greenbone/OpenVAS on kali-tsys, inventory-fed from GLPI (#705 CMDB) so scans cover the whole fleet asset list.
  • cmmc/ — CMMC L3 roadmap, evidence structure, control mapping, reference: Kell Engineering ansible-hardening deployment guide.
  • bor/ — deploy plan for https://github.com/VuteTech/bor
  • pentest/ — pentest tooling + AI-assisted testing exploration (MCP-driven frameworks vs bespoke automation over our own stack).

Working agreements

  • Findings/scan output NEVER leave this repo or Redmine.
  • Prod pentest activity requires an approved GLPI CR + maintenance window.
  • sectestbed VMs are the first targets (see KNEL/PFVCluster change-mgmt map).
S
Description
Compliance & security body of work: STIG/SCAP, CMMC, OpenVAS/GVM, pentest tooling (PRIVATE: vuln data)
Readme AGPL-3.0
107 KiB
Languages
Shell 94%
Makefile 6%