mrcharles f1a423c2b8
ci / audit (push) Successful in 24s
[#389] first discovery scan COMPLETE: 21 findings on sectestbed 5104 — GMP scan pipeline committed
GLPI target → Discovery config → OpenVAS scanner → report
c3294575-3db4-4ad1-8e50-3ca6d23fb137 (18 info, 1 low ICMP-timestamp,
2 unscored). VM shut back down. Pipeline scripts in openvas/scan-pipeline/.
https://projects.knownelement.com/issues/389
2026-09-05 16:04:50 -05:00

KNEL/compliance — compliance & security body of work

STIG/SCAP, CMMC, vulnerability management, and penetration testing for the KNEL fleet. This repo is PRIVATE — it holds vulnerability data, scan results, and security posture detail.

Goal posture (founder mandate, 2026-09-05): CMMC level 3, highest STIG profile, facility clearance track; assume constant pressure from highly skilled, well-resourced attackers. FedRAMP-style audit readiness.

Systems of record

what where
Redmine project compliance-security — umbrella #311
CMMC program #452 gap analysis to CMMC L3 / facility clearance
Related #382 STIG/SCAP, #389 OpenVAS/GVM on kali-tsys, #381 CIS hardening, #379 compliance test lab (sectestbed), #804 second approver
Discourse https://community.turnsys.com/t/338

Layout (seeded 2026-09-05, growth expected)

  • scap/ — SCAP content pipeline: ComplianceAsCode/content profiles driven through Ansible/AWX (KNELIAC security_scap_stig role), OpenSCAP scanning on sectestbed first, then fleet.
  • openvas/ — Greenbone/OpenVAS on kali-tsys, inventory-fed from GLPI (#705 CMDB) so scans cover the whole fleet asset list.
  • cmmc/ — CMMC L3 roadmap, evidence structure, control mapping, reference: Kell Engineering ansible-hardening deployment guide.
  • bor/ — deploy plan for https://github.com/VuteTech/bor
  • pentest/ — pentest tooling + AI-assisted testing exploration (MCP-driven frameworks vs bespoke automation over our own stack).

Working agreements

  • Findings/scan output NEVER leave this repo or Redmine.
  • Prod pentest activity requires an approved GLPI CR + maintenance window.
  • sectestbed VMs are the first targets (see KNEL/PFVCluster change-mgmt map).
S
Description
Compliance & security body of work: STIG/SCAP, CMMC, OpenVAS/GVM, pentest tooling (PRIVATE: vuln data)
Readme AGPL-3.0
107 KiB
Languages
Shell 94%
Makefile 6%