CEM for Linux
You can deploy the Compliance Enforcement Module (CEM) for Linux to help ensure that your servers on Linux operating systems comply with security recommendations. You can enforce the controls that are specified by the Center for Internet Security (CIS). Alternatively, you can apply the standards published in the US Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs).
To get started, review the basic concepts and then follow the instructions to deploy CEM in your environment. See Getting started.
-
Release notes
Review the release notes to learn about updates and resolved issues in the Compliance Enforcement Module (CEM) for Linux. -
Getting started
Learn the basic concepts associated with the Compliance Enforcement Modules and then review the steps for deploying CEM in your environment. -
Installing CEM
Before you install CEM, complete the preparation steps: review the system requirements, install and configure Puppet Enterprise (PE) or open source Puppet, and purchase CEM. To help avoid issues, install and evaluate CEM in a test environment before you install CEM in a production environment. -
Upgrading CEM
You can upgrade CEM for Linux to take advantage of the latest features, fixes, and improvements. To help ensure a smooth upgrade process, complete the preparation tasks first. -
Configuring CEM
Configuration of CEM is optional. If you installed CEM and assigned thecem_linux
class to one or more node groups, the Center for Internet Security (CIS) Server Level 1 profile is enforced automatically during the next Puppet run. However, if the default values leave your infrastructure in an undesirable state, or if you want to customize compliance to meet your organization's requirements, you can configure CEM. -
Auditing and querying issues identified during scans
In some cases, a CIS or DISA STIG compliance scan might identify an issue that you want to investigate and fix. To get started, you can run an audit or query. -
Reference: Benchmarks and controls
For help with configuring CEM, review the CEM Linux Reference on Puppet Forge.