Analysis of existing approaches to application automation for CIS Controls standards and their limitations

DOI: 10.21293/1818-0442-2024-27-4-80-87

Download article in PDF format

JATS xml

Abstract: This article analyzes the existing Bash-based tools for automa-tion of CIS Controls standards, focusing on their capabilities and limitations when applied in corporate environments. Tools such as Ubuntu Security Guide, JShielder, Aqua Security CIS Benchmarks, and JAMF Compliance Reporter are examined. While effective for meeting security requirements, these solu-tions face scalability and centralized management challenges, limiting their use in heterogeneous systems. The article con-cludes with the rationale for using a tool such as Ansible, that has centralized management and automated auditing capabilities, to enable non-continuous CIS compliance in large enterprise infrastructures.

Keywords: automation, CIS Controls, Ansible, information security, Bash, corporate systems, DevOps

For citation:
Vasilevskiy P. A., Bulgakova E. V. Analysis of existing approaches to application automation for CIS Controls standards and their limitations. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2024, vol. 27, no. 4, pp. 80–87. DOI: 10.21293/1818-0442-2024-27-4-80-87

Authors and copyright holders:

  • Vasilevskiy P. A. , Moscow Technical University of Communications and Informatics (Moscow, Russia)
  • Bulgakova E. V. , Moscow Technical University of Communications and Informatics (Moscow, Russia)

  • 1. Gros S. Prompting LLM to Enforce and Validate CIS Critical Security Control. Laboratory for Information Security and Privacy, Faculty of Electrical Engineering and Computing, University of Zagreb, 2020, pp. 1–7.
  • 2. Mohiuddin A., Jinpeng W. Prompting LLM to Enforce and Validate CIS Critical Security Control. Association for Computing Machinery, 2024, pp. 93–104.
  • 3. CIS Debian Linux 12 Benchmark v1.0.1-04-15-2024. Washington.: Center for Internet Security, 2024, 1011 p.
  • 4. CIS Docker Benchmark v1.6.0-06-14-2023. Washington.: Center for Internet Security, 2023, 388 p.
  • 5. Mavrogiannopoulos N. CIS compliance with Ubuntu LTS. Available at: https://discourse.ubuntu.com/t/cis-compliance-with-ubuntu-lts/26084, free (accessed: October 28, 2024).
  • 6. Mavrogiannopoulos N. CIS benchmark compliance: Introducing the Ubuntu Security Guide. Available at: https://ubuntu.com/blog/cis-security-compliance-usg, free (accessed: October 28, 2024).
  • 7. Limniotis K., Kolokotronis N. Threat Actors’ Attack Strategies. Deliverable D2.5, Cyber-Trust. Belgium: Horizon 2020, 2018, 131 p.
  • 8. Jsitech J.S. JShielder Automated Hardening Script for Linux Servers. Available at: https://github.com/Jsitech/JShielder, free (accessed: October 28, 2024).
  • 9. Esage A.G. JShielder Automated Hardening Script for Linux Servers. Available at: https://www.securitynewspaper.com/2018/04/14/jshielder-automated-hardening-script-linux-servers/, free (accessed: October 29, 2024).
  • 10. Ultimate Guide Top 20 Docker Security Best Practices. Available at: https://harmoneyleads.com/Demystify-Demo/pdf/AquaSecurityTop20DockerSecurityBestPractices.pdf, free (accessed: October 28, 2024).
  • 11. CIS Software Supply Chain Security Guide v1.0. Washington: Center for Internet Security, 2022, 66 p.
  • 12. Aqua security receives the 2023. California: Frost & Sullivan, 2024, 8 p.
  • 13. Murugiah S., Morello J. Application Container Security Guide. National Institute of Standards and Technology, 2017, pp. 1–63.
  • 14. CIS-for-macOS-Catalina-CP VS debian-cis. Available at: https://www.libhunt.com/compare-CIS-for-macOS-Catalina-CP-vs-debian-cis, free (accessed: October 29, 2024).
  • 15. CIS for macOS Sierra–Script and Configuration Profile Remediation. Available at: https://github.com/jamf/CIS-for-macOS-Sierra-CP, free (accessed: October 29, 2024).
  • 16. Perminov P., Kosachenko T., Konev A., Shelupanov A. [Automation of information security audit in the Information System on the example of a standard «CIS Palo Alto 8 Firewall Benchmark»]. International Journal of Advanced Trends in Computer Science and Engineering, 2020, vol. 9, no. 2, pp. 2085–2088 (in Russ.).
  • 17. Panasenko L. Max Patrol 8. Overview of the Vulnerability Management. Available at: https://habr.com/ru/companies/tssolution/articles/454976/, free (accessed: November 06, 2024) (in Russ.).
  • 18. MaxPatrol 8. Available at: https://www.ptsecurity.com/ru-ru/products/mp8/#overview, free (accessed: November 06, 2024) (in Russ.).
  • 19. Geerling J. Ansible for DevOps. Server and configuration management for humans. Victoria: Leanpub, 2018, 33 p.
  • 20. Likitha S. Automation of Server Configuration Using Ansible. International Journal for Research in Applied Science and Engineering Technology, 2022, vol. 10, pp. 4109–4113.
  • 21. Berton L. Red Hat Ansible Automation Platform. London: BPB Online, 2024, 369 p.
  • 22. Kouao A. Implementing security benchmarks with Red Hat Ansible Automation Platform. Available at: https://www.redhat.com/en/blog/implementing-security-benchmarks-red-hat-ansible-automation-platform, free (accessed: October 29, 2024).
  • 23. Bird J. DevOpsSec Securing Software through Continuous Delivery. California: O’Reilly Media, 2016, 86 p.
  • 24. Tumbarella S. Systems Hardening Using the CIS Benchmarks & Ansible Copy. Available at: https://foghornconsulting.com/2021/08/23/system-hardening-with-ansible-copy/, free (accessed: October 29, 2024).
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates