Ansible-lockdown Logo

Introduction

  • Automated Security Benchmark - Auditing and Remediation
    • MindPoint Group - A Tyto Athene Company’s (TYTO) Ansible-Lockdown Overview
    • Why should this role be applied to a system?
    • What is security hardening?
      • CIS Overview
        • What is CIS?
        • What do the CIS roles do?
        • Control Severities
      • STIG Overview
        • What is STIG?
        • What do the STIG roles do?
        • Control Severities
    • What is provided?
    • How is this written?
    • Development Process
      • Lifecycle of releases and branches
      • Branches
      • Remediate
      • Audit
      • Demos

Getting Started

  • Audit
    • Overview
    • Considerations
    • Currently Enabled Playbooks
    • Setup auditing as standalone
    • Running the Audit Only as part of remediate playbook
    • Defining the audit
    • Running on Linux
      • Bash Script Explanation: Goss Security Audit
    • Fetch or Copy Audit Files
    • Running on Windows
      • PowerShell Script Explanation: Goss Security Audit
  • Remediate
    • Requirements
    • Installation
      • Using ansible-galaxy
      • Using git
    • How to Use
      • On Its Own
      • With Existing Playbooks
      • Variables and the Role
      • Using and Modifying Variables Directly (defaults/main.yml)
      • Modifying Variables with Extra-Vars
      • Using Tags
  • Using Audit and Remediate together
  • Post Hardening Lockdown Reporting via Ansible_Facts
    • Lockdown Facts Example:
      • CIS
      • STIG
  • Container and Docker Guide
    • Overview
    • Container Detection
    • Controls Skipped in Containers
    • Running Audit in Containers
      • Audit from Host Against Container
    • Running Remediation in Containers
      • Building Hardened Container Images
      • Remediating Running Containers
    • Known Limitations
    • Best Practices
    • Troubleshooting
  • ARM64/aarch64 Architecture Guide
    • Overview
    • Support Status
    • Getting Started on ARM64
      • Prerequisites
      • Running Remediation
      • Running Audit
    • Known Limitations
      • auditd System Call Differences
      • Kernel Module Differences
      • Validation Steps
    • Troubleshooting
      • Audit Binary Issues
      • auditd Rule Failures
    • Reporting ARM64 Issues
    • Best Practices

Available Content

  • Release Schedule
    • CIS
    • STIG
    • Playbook Releases
      • Example
  • CIS Benchmarks
    • Operating Systems
    • Cloud Platforms
    • Applications
    • Archived Roles
  • CIS Specific Information
    • Advanced Options
  • STIG Benchmarks
    • Operating Systems
    • Networking
    • Applications
    • Archived Roles

Development

  • Contributing
    • How to contribute to audit development
      • Adding code
      • Considerations
      • Layout
        • Content
        • Metadata
      • Gotchas
    • How to Contribute to Remediate Development
      • Remediate Code Summary
      • Remediate Code Considerations
        • General Layout
        • Variables
        • STIG Control Task Layout
        • CIS Control Task Layout

Support

  • Getting Support
    • Contact Us
    • Tyto Athene Official Site and Services

Reference & Appendices

  • Glossary
  • Useful links
    • Support
    • Main Content site
    • Audit
    • Remediate
      • Linting
Ansible-lockdown
  • Documentation

Documentation

Introduction

  • Automated Security Benchmark - Auditing and Remediation

Getting Started

  • Audit
    • Overview
    • Considerations
    • Currently Enabled Playbooks
    • Setup auditing as standalone
    • Running the Audit Only as part of remediate playbook
    • Defining the audit
    • Running on Linux
    • Fetch or Copy Audit Files
    • Running on Windows
  • Remediate
    • Requirements
    • Installation
    • How to Use
  • Using Audit and Remediate together
  • Post Hardening Lockdown Reporting via Ansible_Facts
    • Lockdown Facts Example:
  • Container and Docker Guide
    • Overview
    • Container Detection
    • Controls Skipped in Containers
    • Running Audit in Containers
    • Running Remediation in Containers
    • Known Limitations
    • Best Practices
    • Troubleshooting
  • ARM64/aarch64 Architecture Guide
    • Overview
    • Support Status
    • Getting Started on ARM64
    • Known Limitations
    • Troubleshooting
    • Reporting ARM64 Issues
    • Best Practices

Available Content

  • Release Schedule
    • CIS
    • STIG
    • Playbook Releases
  • CIS Benchmarks
    • Operating Systems
    • Cloud Platforms
    • Applications
    • Archived Roles
  • CIS Specific Information
    • Advanced Options
  • STIG Benchmarks
    • Operating Systems
    • Networking
    • Applications
    • Archived Roles

Development

  • Contributing
    • How to contribute to audit development
    • How to Contribute to Remediate Development

Support

  • Getting Support
    • Contact Us
    • Tyto Athene Official Site and Services

Reference & Appendices

  • Glossary
  • Useful links
    • Support
    • Main Content site
    • Audit
    • Remediate
Next

© Copyright 2026, MindPoint Group - A Tyto Athene Company. Last updated on 2026-04-07 12:29.

Built with Sphinx using a theme provided by Read the Docs.