Dale Bingham
1 min readOct 7, 2020

--

Tony, for now we are using the STIGs from https://public.cyber.mil/ and those that are compatible. That was honestly our biggest pain point ourselves and the problem we were looking to solve. We did DISA first, then added the Tennable scan output to upload and use. We have not looked at this one yet but now it is on our radar. So thank you. Right now, I do not know what it will do. But we probably would need to write a parser to pull it in. I put a ticket in to do this https://github.com/Cingulara/openrmf-docs/issues/195.

We do work with the SQL Server checklist CKL files that are produced and made with the DISA Java Viewer. So once the data is in there, it will work well.

We are up to version 1.2 of the tool now so it may offer benefits to use with all checklists / SCAP scans once in the right format. But that step of putting the SQL ones into the checklist would be manual for this question right now.

I believe you are referring to the https://borellisecuritysoftware.com/collections/all correct? I have not used this yet but we can add that to our listing to work with. Feel free to elaborate on the ticket I listed above to add further info. The https://www.openrmf.io/ website also lists the SLACK channel you can pop info/questions into as well.

--

--

Dale Bingham
Dale Bingham

Written by Dale Bingham

CEO of Soteria Software. Developer on OpenRMF. Software Geek by trade. Father of three daughters. Husband. Love new tech where it fits. Follow at @soteriasoft

No responses yet