Auditing

Dalet Flex allows for additional security auditing tools should be installed.

Info

This may comes in handy when attempting to perform a security status self-assessment, if you intend for ISO27001 or SOC-2 compliance for example.

If desired, one can simply turn the following variable on in ansible/vars/variables.yml file:

dalet_baseos_security_auditing_enabled: true

Once enabled, you can play back your infrastructure through:

$ opsctl deploy -p dalet.flex.infra

and deployment logs will provide you with security assessment score from Lynis.

Lynis will perform various security checks on the system (how the different packages are configured, who can escalates to admin rights, how, if some key files have excessive read rights ...) and provides you with its assessment.

Warning

The assessment report and analysis is up to organization and depends on your own security standards. What's good enough for some might be insufficient for others and there's no specific threshold of what is 'secure' and what is not.

If you're very much concerned about the global security, especially in the long run, it is possible to enforce auditing at playbook runtime through the following:

dalet_baseos_security_auditing_enforced: true
dalet_baseos_security_auditing_minimal_score: 69

Doing so implies that, when running the playbook, Lynis will perform its self-assessment and the run will fail if a minimal compliance of 69% has not been reached (preventing for example from strong initial compliance, later to be loosen by various updates over time).