Анализ существующих подходов к автоматизации применения стандартов CIS Controls и их ограничений

DOI: 10.21293/1818-0442-2024-27-4-80-87

Скачать текст статьи в формате PDF

Скачать JATS xml

Аннотация: Проводится анализ существующих инструментов автоматизации стандартов CIS Controls на базе bash, включая их функциональные возможности и ограничения при применении в корпоративных средах. Рассматриваются такие инструменты, как Ubuntu Security Guide, JShielder, Aqua Security CIS Benchmarks и JAMF Compliance Reporter. Указанные решения, хотя и эффективны для выполнения требований безопасности, сталкиваются с проблемами масштабирования и централизованного управления, что ограничивает их применение в гетерогенных системах. В заключении статьи обоснована целесообразность использования инструмента, такого как Ansible, обладающего возможностями для централизованного управления и автоматизированного аудита, что позволяет обеспечить не-прерывное соблюдение требований CIS в крупных корпоративных инфраструктурах.

Ключевые слова: автоматизация, CIS Controls, Ansible, безопасность информации, bash, корпоративные системы, DevOps

Библиография статьи:
Василевский П. А. Анализ существующих подходов к автоматизации применения стандартов CIS Controls и их ограничений / П. А. Василевский, Е. В. Булгакова // Доклады Томского государственного университета систем управления и радиоэлектроники. – 2024. – Т. 27, № 4. – С. 80–87. DOI: 10.21293/1818-0442-2024-27-4-80-87

Авторы и правообладатели:

  • Василевский П. А. , Московский технический университет связи и информатики (Москва, Россия)
  • Булгакова Е. В. , Московский технический университет связи и информатики (Москва, Россия)

  • 1. Gros S. Prompting LLM to Enforce and Validate CIS Critical Security Control // Laboratory for Information Security and Privacy, Faculty of Electrical Engineering and Computing, University of Zagreb. – 2020. – P. 1–7.
  • 2. Mohiuddin A. Proceedings of the 29th ACM Symposium on Access Control Models and Technologies – 2024: Prompting LLM to Enforce and Validate CIS Critical Security Control / A. Mohiuddin, W. Jinpeng // Association for Computing Machinery. – 2024. – P. 93–104.
  • 3. CIS Debian Linux 12 Benchmark v1.0.1-04-15-2024. – Washington.: Center for Internet Security, 2024. – 1011 p.
  • 4. CIS Docker Benchmark v1.6.0-06-14-2023. – Washington: Center for Internet Security, 2023. – 388 p.
  • 5. Mavrogiannopoulos N. CIS compliance with Ubuntu LTS [Электронный ресурс]. – Режим доступа: https://discourse.ubuntu.com/t/cis-compliance-with-ubuntults/26084, свободный (дата обращения: 28.10.2024).
  • 6. Mavrogiannopoulos N. CIS benchmark compliance: Introducing the Ubuntu Security Guide [Электронный ресурс]. – Режим доступа: https://ubuntu.com/blog/cis-securitycompliance-usg, свободный (дата обращения: 28.10.2024).
  • 7. Limniotis K. Threat Actors’ Attack Strategies. Deliverable D2.5, Cyber-Trust Consortium / K. Limniotis, N. Kolokotronis. – Belgium: Horizon–2020, 2018. – 131 p.
  • 8. Jsitech J.S. JShielder Automated Hardening Script for Linux Servers [Электронный ресурс]. – Режим доступа: https://github.com/Jsitech/JShielder, свободный (дата обращения: 28.10.2024).
  • 9. Esage A.G. JShielder Automated Hardening Script for Linux Servers [Электронный ресурс]. – Режим доступа: https://www.securitynewspaper.com/2018/04/14/jshielderautomated-hardening-script-linux-servers, свободный (дата обращения: 28.10.2024).
  • 10. Ultimate Guide Top 20 Docker Security Best Practices [Электронный ресурс]. – Режим доступа: https://harmoneyleads.com/Demystify-Demo/pdf/AquaSecurityTop20DockerSecurityBestPractices.pdf, свободный (дата обращения: 28.10.2024).
  • 11. CIS Software Supply Chain Security Guide v1.0. – Washington: Center for Internet Security, 2022. – 66 p.
  • 12. Aqua security receives the 2023. – California: Frost & Sullivan, 2024. – 8 p.
  • 13. Murugiah S. Application Container Security Guide / S. Murugiah, J. Morello // National Institute of Standards and Technology. – 2017. – P. 1–63.
  • 14. CIS-for-macOS-Catalina-CP VS debian-cis [Электронный ресурс]. – Режим доступа: https://www.libhunt.com/compare-CIS-for-macOS-Catalina-CP-vs-debian-cis, свободный (дата обращения: 29.10.2024).
  • 15. jamf CIS for macOS Sierra-Script and Configuration Profile Remediation / jamf [Электронный ресурс]. – Режим доступа: https://github.com/jamf/CIS-for-macOS-Sierra-CP, свободный (дата обращения: 29.10.2024).
  • 16. Automation of information security audit in the Information System on the example of a standard «CIS Palo Alto 8 Firewall Benchmark» / P. Perminov, T. Kosachenko, A. Konev, A. Shelupanov // International Journal of Advanced Trends in Computer Science and Engineering. – 2020. – Vol. 9, No. 2. – P. 2085–2088.
  • 17. Panasenko L. Max Patrol 8. Обзор инструмента для управления уязвимостями [Электронный ресурс]. – Режим доступа: https://habr.com/ru/compa-nies/tssolution/articles/454976, свободный (дата обращения: 06.11.2024).
  • 18. MaxPatrol 8 [Электронный ресурс]. – Режим доступа: https://www.ptsecurity.com/ru-ru/products/mp8/#overview, свободный (дата обращения: 06.11.2024).
  • 19. Geerling J. Ansible for DevOps. Server and configuration management for humans. – Victoria: Leanpub, 2018. – 33 p.
  • 20. Likitha S. Automation of Server Configuration Using Ansible // International Journal for Research in Applied Science and Engineering Technology. – 2022. – Vol. 10. – P. 4109–4113.
  • 21. Berton L. Red Hat Ansible Automation Platform. – London: BPB Online, 2024. – 369 p.
  • 22. Kouao A. Implementing security benchmarks with Red Hat Ansible Automation Platform [Электронный ресурс]. – Режим доступа: https://www.redhat.com/en/blog/implementing-security-benchmarks-red-hat-ansible-automationplatform, свободный (дата обращения: 29.10.2024).
  • 23. Bird J. DevOpsSec Securing Software through Continuous Delivery. – California: O’Reilly Media, 2016. – 86 p.
  • 24. Tumbarella S. Systems Hardening Using the CIS Benchmarks & Ansible Copy [Электронный ресурс]. – Режим доступа: https://foghornconsulting.com/2021/08/23/system-hardening-with-ansible-copy, свободный (дата обращения: 29.10.2024).
Адрес редакции

  634050, г. Томск, пр. Ленина, 40, МК, каб. 310/2

  (3822) 701-582, внутр.: 1456

  journal@tusur.ru