mrcharles 8eab675c74
ci / audit (push) Successful in 20s
[#389] GLPI→OpenVAS feed pilot: script (fixture-tested, 63 targets) + GVM app-test compose + pipeline docs
Feed reads GLPI computers read-only (mglpi identity), parses ts=/mgmt IP
comment convention, emits CSV or GMP create_target fragments. Dual
shellcheck green. GVM stack = Greenbone community containers, loopback.
https://projects.knownelement.com/issues/389
2026-09-05 06:56:00 -05:00

KNEL/compliance — compliance & security body of work

STIG/SCAP, CMMC, vulnerability management, and penetration testing for the KNEL fleet. This repo is PRIVATE — it holds vulnerability data, scan results, and security posture detail.

Goal posture (founder mandate, 2026-09-05): CMMC level 3, highest STIG profile, facility clearance track; assume constant pressure from highly skilled, well-resourced attackers. FedRAMP-style audit readiness.

Systems of record

what where
Redmine project compliance-security — umbrella #311
CMMC program #452 gap analysis to CMMC L3 / facility clearance
Related #382 STIG/SCAP, #389 OpenVAS/GVM on kali-tsys, #381 CIS hardening, #379 compliance test lab (sectestbed), #804 second approver
Discourse https://community.turnsys.com/t/338

Layout (seeded 2026-09-05, growth expected)

  • scap/ — SCAP content pipeline: ComplianceAsCode/content profiles driven through Ansible/AWX (KNELIAC security_scap_stig role), OpenSCAP scanning on sectestbed first, then fleet.
  • openvas/ — Greenbone/OpenVAS on kali-tsys, inventory-fed from GLPI (#705 CMDB) so scans cover the whole fleet asset list.
  • cmmc/ — CMMC L3 roadmap, evidence structure, control mapping, reference: Kell Engineering ansible-hardening deployment guide.
  • bor/ — deploy plan for https://github.com/VuteTech/bor
  • pentest/ — pentest tooling + AI-assisted testing exploration (MCP-driven frameworks vs bespoke automation over our own stack).

Working agreements

  • Findings/scan output NEVER leave this repo or Redmine.
  • Prod pentest activity requires an approved GLPI CR + maintenance window.
  • sectestbed VMs are the first targets (see KNEL/PFVCluster change-mgmt map).
S
Description
Compliance & security body of work: STIG/SCAP, CMMC, OpenVAS/GVM, pentest tooling (PRIVATE: vuln data)
Readme AGPL-3.0
107 KiB
Languages
Shell 94%
Makefile 6%