Skip to content

Commit 31ca89c

Browse files
authored
Merge pull request #102871 from openshift-cherrypick-robot/cherry-pick-102581-to-enterprise-4.17
[enterprise-4.17] CMP-3717: Update supported profiles documentation
2 parents 9350c0a + 06e63f8 commit 31ca89c

File tree

1 file changed

+39
-101
lines changed

1 file changed

+39
-101
lines changed

modules/compliance-supported-profiles.adoc

Lines changed: 39 additions & 101 deletions
Original file line numberDiff line numberDiff line change
@@ -30,32 +30,14 @@ The following tables reflect the latest available profiles in the Compliance Ope
3030
|ocp4-cis ^[1]^
3131
|CIS Red Hat OpenShift Container Platform Benchmark v1.7.0
3232
|Platform
33-
|link:https://www.cisecurity.org/cis-benchmarks/[CIS Benchmarks ™] ^[1]^
34-
|`x86_64`
35-
`ppc64le`
36-
`s390x`
37-
`aarch64`
38-
|
39-
40-
|ocp4-cis-1-4 ^[3]^
41-
|CIS Red Hat OpenShift Container Platform Benchmark v1.4.0
42-
|Platform
43-
|link:https://www.cisecurity.org/cis-benchmarks/[CIS Benchmarks ™] ^[4]^
44-
|`x86_64`
45-
`ppc64le`
46-
`s390x`
47-
|
48-
49-
|ocp4-cis-1-5
50-
|CIS Red Hat OpenShift Container Platform Benchmark v1.5.0
51-
|Platform
5233
|link:https://www.cisecurity.org/cis-benchmarks/[CIS Benchmarks ™] ^[4]^
5334
|`x86_64`
5435
`ppc64le`
5536
`s390x`
37+
`aarch64`
5638
|
5739

58-
|ocp4-cis-1-7
40+
|ocp4-cis-1-7^[3]^
5941
|CIS Red Hat OpenShift Container Platform Benchmark v1.7.0
6042
|Platform
6143
|link:https://www.cisecurity.org/cis-benchmarks/[CIS Benchmarks ™] ^[4]^
@@ -75,25 +57,7 @@ The following tables reflect the latest available profiles in the Compliance Ope
7557
`aarch64`
7658
|{product-rosa} with {hcp} (ROSA HCP)
7759

78-
|ocp4-cis-node-1-4 ^[3]^
79-
|CIS Red Hat OpenShift Container Platform Benchmark v1.4.0
80-
|Node ^[2]^
81-
|link:https://www.cisecurity.org/cis-benchmarks/[CIS Benchmarks ™] ^[4]^
82-
|`x86_64`
83-
`ppc64le`
84-
`s390x`
85-
|{product-rosa} with {hcp} (ROSA HCP)
86-
87-
|ocp4-cis-node-1-5
88-
|CIS Red Hat OpenShift Container Platform Benchmark v1.5.0
89-
|Node ^[2]^
90-
|link:https://www.cisecurity.org/cis-benchmarks/[CIS Benchmarks ™] ^[4]^
91-
|`x86_64`
92-
`ppc64le`
93-
`s390x`
94-
|{product-rosa} with {hcp} (ROSA HCP)
95-
96-
|ocp4-cis-node-1-7
60+
|ocp4-cis-node-1-7^[3]^
9761
|CIS Red Hat OpenShift Container Platform Benchmark v1.7.0
9862
|Node ^[2]^
9963
|link:https://www.cisecurity.org/cis-benchmarks/[CIS Benchmarks ™] ^[4]^
@@ -105,9 +69,9 @@ The following tables reflect the latest available profiles in the Compliance Ope
10569

10670
|===
10771
[.small]
108-
1. The `ocp4-cis` and `ocp4-cis-node` profiles maintain the most up-to-date version of the CIS benchmark as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as CIS v1.4.0, use the `ocp4-cis-1-4` and `ocp4-cis-node-1-4` profiles.
72+
1. The `ocp4-cis` and `ocp4-cis-node` profiles maintain the most up-to-date version of the CIS benchmark as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as CIS v1.7.0, use the `ocp4-cis-1-7` and `ocp4-cis-node-1-7` profiles.
10973
2. Node profiles must be used with the relevant Platform profile. For more information, see _Compliance Operator profile types_.
110-
3. CIS v1.4.0 is superceded by CIS v1.5.0. It is recommended to apply the latest profile to your environment.
74+
3. All earlier CIS profiles are superceded by CIS v1.7.0. It is recommended to apply the latest profile to your environment.
11175
4. To locate the CIS {product-title} v4 Benchmark, go to link:https://www.cisecurity.org/benchmark/kubernetes[CIS Benchmarks] and click *Download Latest CIS Benchmark*, where you can then register to download the benchmark.
11276

11377
[id="bsi-profiles_{context}"]
@@ -152,6 +116,21 @@ The following tables reflect the latest available profiles in the Compliance Ope
152116
|`x86_64`
153117
|
154118

119+
|rhcos4-bsi ^[3]^
120+
|BSI IT-Grundschutz (Basic Protection) Building Block SYS.1.6 and APP.4.4
121+
|Node ^[2]^
122+
|link:https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf[BSI Basic Protection Compendium]
123+
|`x86_64`
124+
|
125+
126+
|ocp4-bsi-2022 ^[3]^
127+
|BSI IT-Grundschutz (Basic Protection) Building Block SYS.1.6 and APP.4.4
128+
|Node ^[2]^
129+
|link:https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf[BSI Basic Protection Compendium]
130+
|`x86_64`
131+
|
132+
133+
155134
|===
156135
[.small]
157136
1. The `ocp4-bsi` and `ocp4-bsi-node` profiles maintain the most up-to-date version of the BSI Basic Protection Profile as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as BSI 2022, use the `ocp4-bsi-2022` and `ocp4-bsi-node-2022` profiles.
@@ -390,6 +369,7 @@ Applying automatic remedations to any profile, such as `rhcos4-stig`, that uses
390369
|link:https://www.pcisecuritystandards.org/document_library?document=pci_dss[PCI Security Standards ® Council Document Library]
391370
|`x86_64`
392371
`ppc64le`
372+
`aarch64`
393373
|
394374

395375
|ocp4-pci-dss-3-2 ^[3]^
@@ -399,6 +379,7 @@ Applying automatic remedations to any profile, such as `rhcos4-stig`, that uses
399379
|`x86_64`
400380
`ppc64le`
401381
`s390x`
382+
`aarch64`
402383
|
403384

404385
|ocp4-pci-dss-4-0
@@ -407,6 +388,7 @@ Applying automatic remedations to any profile, such as `rhcos4-stig`, that uses
407388
|link:https://www.pcisecuritystandards.org/document_library?document=pci_dss[PCI Security Standards ® Council Document Library]
408389
|`x86_64`
409390
`ppc64le`
391+
`aarch64`
410392
|
411393

412394
|ocp4-pci-dss-node ^[1]^
@@ -415,6 +397,7 @@ Applying automatic remedations to any profile, such as `rhcos4-stig`, that uses
415397
|link:https://www.pcisecuritystandards.org/document_library?document=pci_dss[PCI Security Standards ® Council Document Library]
416398
|`x86_64`
417399
`ppc64le`
400+
`aarch64`
418401
|{product-rosa} with {hcp} (ROSA HCP)
419402

420403
|ocp4-pci-dss-node-3-2 ^[3]^
@@ -424,6 +407,7 @@ Applying automatic remedations to any profile, such as `rhcos4-stig`, that uses
424407
|`x86_64`
425408
`ppc64le`
426409
`s390x`
410+
`aarch64`
427411
|{product-rosa} with {hcp} (ROSA HCP)
428412

429413
|ocp4-pci-dss-node-4-0
@@ -432,6 +416,7 @@ Applying automatic remedations to any profile, such as `rhcos4-stig`, that uses
432416
|link:https://www.pcisecuritystandards.org/document_library?document=pci_dss[PCI Security Standards ® Council Document Library]
433417
|`x86_64`
434418
`ppc64le`
419+
`aarch64`
435420
|{product-rosa} with {hcp} (ROSA HCP)
436421
|===
437422

@@ -460,95 +445,48 @@ Applying automatic remedations to any profile, such as `rhcos4-stig`, that uses
460445
|Supported platforms
461446

462447
|ocp4-stig ^[1]^
463-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift
448+
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift^[3]^
464449
|Platform
465450
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
466451
|`x86_64`
467452
`ppc64le`
468453
|
469454

470455
|ocp4-stig-node ^[1]^
471-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift
472-
|Node ^[2]^
473-
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
474-
|`x86_64`
475-
`ppc64le`
476-
|{product-rosa} with {hcp} (ROSA HCP)
477-
478-
|ocp4-stig-node-v1r1 ^[3]^
479-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V1R1
480-
|Node ^[2]^
481-
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
482-
|`x86_64`
483-
`ppc64le`
484-
|{product-rosa} with {hcp} (ROSA HCP)
485-
486-
|ocp4-stig-node-v2r1
487-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V2R1
488-
|Node ^[2]^
489-
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
490-
|`x86_64`
491-
`ppc64le`
492-
|{product-rosa} with {hcp} (ROSA HCP)
493-
494-
|ocp4-stig-node-v2r2
495-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V2R2
456+
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift^[3]^
496457
|Node ^[2]^
497458
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
498459
|`x86_64`
499460
`ppc64le`
500461
|{product-rosa} with {hcp} (ROSA HCP)
501462

502-
|ocp4-stig-v1r1 ^[3]^
503-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V1R1
504-
|Platform
505-
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
506-
|`x86_64`
507-
`ppc64le`
508-
|
509463

510-
|ocp4-stig-v2r1
511-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V2R1
464+
|ocp4-stig-v2r3
465+
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V2R3
512466
|Platform
513467
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
514468
|`x86_64`
515469
`ppc64le`
516470
|
517471

518-
|ocp4-stig-v2r2
519-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V2R2
520-
|Platform
521-
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
522-
|`x86_64`
523-
`ppc64le`
524-
|
525-
526-
|rhcos4-stig
527-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift
472+
|ocp4-stig-node-v2r3 ^[1]^
473+
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V2R3
528474
|Node
529475
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
530476
|`x86_64`
531477
`ppc64le`
532-
|{product-rosa} with {hcp} (ROSA HCP)
533-
534-
|rhcos4-stig-v1r1 ^[3]^
535-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V1R1
536-
|Node
537-
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG] ^[3]^
538-
|`x86_64`
539-
`ppc64le`
540-
|{product-rosa} with {hcp} (ROSA HCP)
478+
|
541479

542-
|rhcos4-stig-v2r1
543-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V2R1
480+
|rhcos4-stig^[1]^
481+
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift^[3]^
544482
|Node
545483
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
546484
|`x86_64`
547485
`ppc64le`
548486
|{product-rosa} with {hcp} (ROSA HCP)
549487

550-
|rhcos4-stig-v2r2
551-
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V2R2
488+
|rhcos4-stig-v2r3
489+
|Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat Openshift V2R3
552490
|Node
553491
|link:https://public.cyber.mil/stigs/downloads/[DISA-STIG]
554492
|`x86_64`
@@ -557,9 +495,9 @@ Applying automatic remedations to any profile, such as `rhcos4-stig`, that uses
557495

558496
|===
559497
[.small]
560-
1. The `ocp4-stig`, `ocp4-stig-node` and `rhcos4-stig` profiles maintain the most up-to-date version of the DISA-STIG benchmark as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as DISA-STIG V2R1, use the `ocp4-stig-v2r1` and `ocp4-stig-node-v2r1` profiles.
498+
1. The `ocp4-stig`, `ocp4-stig-node` and `rhcos4-stig` profiles maintain the most up-to-date version of the DISA-STIG benchmark as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as DISA-STIG V2R3, use the `ocp4-stig-v2r3` and `ocp4-stig-node-v2r3` profiles.
561499
2. Node profiles must be used with the relevant Platform profile. For more information, see _Compliance Operator profile types_.
562-
3. DISA-STIG V1R1 is superceded by DISA-STIG V2R1. It is recommended to apply the latest profile to your environment.
500+
3. DISA-STIG V1R2 is superceded by DISA-STIG V2R3. It is recommended to apply the latest profile to your environment.
563501

564502
[id="compliance-extended-profiles_{context}"]
565503
== About extended compliance profiles

0 commit comments

Comments
 (0)