# KNEL/compliance — compliance & security body of work STIG/SCAP, CMMC, vulnerability management, and penetration testing for the KNEL fleet. **This repo is PRIVATE** — it holds vulnerability data, scan results, and security posture detail. Goal posture (founder mandate, 2026-09-05): CMMC **level 3**, highest STIG profile, facility clearance track; assume constant pressure from highly skilled, well-resourced attackers. FedRAMP-style audit readiness. ## Systems of record | what | where | |---|---| | Redmine project | [compliance-security](https://projects.knownelement.com/projects/compliance-security) — umbrella [#311](https://projects.knownelement.com/issues/311) | | CMMC program | [#452](https://projects.knownelement.com/issues/452) gap analysis to CMMC L3 / facility clearance | | Related | [#382](https://projects.knownelement.com/issues/382) STIG/SCAP, [#389](https://projects.knownelement.com/issues/389) OpenVAS/GVM on kali-tsys, [#381](https://projects.knownelement.com/issues/381) CIS hardening, [#379](https://projects.knownelement.com/issues/379) compliance test lab (sectestbed), [#804](https://projects.knownelement.com/issues/804) second approver | | Discourse | compliance topic (link lands at repo birth) | ## Layout (seeded 2026-09-05, growth expected) - `scap/` — SCAP content pipeline: [ComplianceAsCode/content](https://github.com/ComplianceAsCode/content) profiles driven through Ansible/AWX (KNELIAC `security_scap_stig` role), OpenSCAP scanning on sectestbed first, then fleet. - `openvas/` — Greenbone/OpenVAS on kali-tsys, inventory-fed from GLPI (#705 CMDB) so scans cover the whole fleet asset list. - `cmmc/` — CMMC L3 roadmap, evidence structure, control mapping, reference: Kell Engineering ansible-hardening deployment guide. - `bor/` — deploy plan for https://github.com/VuteTech/bor - `pentest/` — pentest tooling + AI-assisted testing exploration (MCP-driven frameworks vs bespoke automation over our own stack). ## Working agreements - Findings/scan output NEVER leave this repo or Redmine. - Prod pentest activity requires an approved GLPI CR + maintenance window. - sectestbed VMs are the first targets (see KNEL/PFVCluster change-mgmt map).