OCP 5.0 Remediation Groupings

← Back to OCP 5.0 Compliance Status | View Detailed Group Pages

This page catalogs all compliance remediation groups for OCP 5.0, dynamically generated from tracking data.

Target baseline: RHCOS 10.2 (OCP 5.0) with compliance-operator and pinned content image.

Scan Environment — 2026-08-12
Content Imagequay.io/bapalm/k8scontent:v0.1.81
Operator Imageghcr.io/complianceascode/compliance-operator:latest
Scanner Imageghcr.io/complianceascode/openscap-ocp:latest
Scan Date2026-08-12 17:45 UTC

Quick Summary

StatusCount
✅ PASS on vanilla RHCOS 10.2+5 groups
🟢 Verified (remediation works)0 groups
🔵 In Progress0 groups
🟡 Pending34 groups
🟠 Partial0 groups
📋 Manual5 groups
Scan Change Log — Untracked check status changes between scans
2026-08-12 (vs 2026-07-21)
  • ocp4-moderate-cluster-version-operator-exists: PASSFAIL OCP
    CVO pod may have been restarting during scan on freshly provisioned nightly cluster
  • ocp4-moderate-resource-requests-limits-in-deployment: FAILPASS OCP
    OCP 5.0 nightly 2026-08-11 ships with resource limits on default operator deployments
  • ocp4-moderate-route-ip-whitelist: FAILPASS OCP
    Default route configuration in this nightly includes IP whitelist annotation
  • ocp4-moderate-routes-rate-limit: FAILPASS OCP
    Default route configuration in this nightly includes rate-limit annotation

Remediation Status

Group Category Platform Severity Checks Status Upstream Compare Jira PR
H1 Crypto Policy RHCOS HIGH 1 🟡 Pending 🎯 RAN Only 📦 - -
H2 PAM Empty Passwords RHCOS HIGH 1 verified-needed 🟣 PR Open 📦 CNF-22661 -
H3 SSHD Empty Passwords RHCOS HIGH 1 ✅ PASS (vanilla) ✅ Pass - - -
M1 SSHD Configuration RHCOS MEDIUM 7 ✅ PASS (vanilla) ✅ Pass - - -
M2 Kernel Hardening (Sysctl) RHCOS MEDIUM 4 ✅ PASS (vanilla) ✅ Pass - - -
M3 Audit Rules - DAC Modifications RHCOS MEDIUM 2 🟡 Pending 🎯 RAN Only 📦 - -
M4 Audit Rules - SELinux RHCOS MEDIUM 6 🟡 Pending 🎯 RAN Only 📦 - -
M5 Audit Rules - Kernel Modules RHCOS MEDIUM 3 🟡 Pending 🎯 RAN Only 📦 - -
M6 Audit Rules - Time Modifications RHCOS MEDIUM 5 🟡 Pending 🎯 RAN Only 📦 - -
M7 Audit Rules - Login Monitoring RHCOS MEDIUM 6 🟡 Pending 🎯 RAN Only 📦 - -
M8 Audit Rules - Network Config RHCOS MEDIUM 1 🟡 Pending 🎯 RAN Only 📦 - -
M9 Auditd Configuration RHCOS MEDIUM 1 🟡 Pending 🎯 RAN Only 📦 - -
M10 API Server Encryption OCP MEDIUM 1 🟡 Pending ⚙️ Platform 📦 - -
M11 Ingress TLS Ciphers OCP MEDIUM 1 ✅ PASS (vanilla) ✅ Pass - - -
M12 Audit Profile OCP MEDIUM 1 🟡 Pending ⚙️ Platform 📦 - -
L1 SSHD LogLevel RHCOS LOW 1 ✅ PASS (vanilla) ✅ Pass - - -
L2 Sysctl dmesg_restrict RHCOS LOW 1 🟡 Pending ✅ Pass 📦 - -
M13 Extended DAC Audit RHCOS MEDIUM 11 🟡 Pending 🎯 RAN Only 📦 - -
M14 Identity File Access Audit RHCOS MEDIUM 12 🟡 Pending 🎯 RAN Only 📦 - -
M15 File Deletion Audit RHCOS MEDIUM 5 🟡 Pending 🎯 RAN Only 📦 - -
M16 Unsuccessful File Modification Audit RHCOS MEDIUM 32 🟡 Pending 🎯 RAN Only 📦 - -
M17 Privileged Commands Audit RHCOS MEDIUM 22 🟡 Pending 🎯 RAN Only 📦 - -
M18 Session & MAC Audit RHCOS MEDIUM 4 🟡 Pending 🎯 RAN Only 📦 - -
M19 Usergroup Modification Audit RHCOS MEDIUM 5 🟡 Pending 🎯 RAN Only 📦 - -
M20 Auditd Data Retention RHCOS MEDIUM 4 🟡 Pending 🎯 RAN Only 📦 - -
M21 Kernel Module Blacklist RHCOS MEDIUM 18 🟡 Pending 🟣 PR Open 📦 CNF-25994 -
M22 Network Sysctl Hardening RHCOS MEDIUM 20 🟡 Pending 🎯 RAN Only 📦 - -
M23 Kernel Sysctl Extended RHCOS MEDIUM 3 🟡 Pending 🎯 RAN Only 📦 - -
M24 CoreOS Kernel Arguments RHCOS MEDIUM 6 🟡 Pending 🎯 RAN Only 📦 - -
M25 Chrony/NTP Configuration RHCOS MEDIUM 4 🟡 Pending 📍 Site 📦 - -
M26 Systemd Hardening RHCOS MEDIUM 6 🟡 Pending 🎯 RAN Only 📦 - -
M27 SSHD Moderate Extensions RHCOS MEDIUM 2 🟡 Pending 🎯 RAN Only 📦 - -
M28 USBGuard RHCOS MEDIUM 3 🟡 Pending — N/A 📦 - -
M29 System Access Controls Mixed MEDIUM 7 🟡 Pending ⚙️ Platform 📦 - -
M30 OAuth Configuration Mixed MEDIUM 2 🟡 Pending ⚙️ Platform 📦 - -
MAN1 Workload Security OCP MANUAL 19 🟡 Pending — N/A - - -
MAN2 RBAC & Access Control OCP MANUAL 7 🟡 Pending — N/A - - -
MAN3 Secrets Management OCP MANUAL 2 🟡 Pending — N/A - - -
MAN4 Audit Log Partitions OCP MANUAL 5 🟡 Pending — N/A - - -
MAN5 Hardware/BIOS & Alerting OCP MANUAL 17 🟡 Pending — N/A - - -

Remediation Details

H1: Crypto Policy — 🟡 Pending
CheckDescription
configure-crypto-policySystem-wide crypto policy (DEFAULT:NO-SHA1)
H2: PAM Empty Passwords — verified-needed

Jira: CNF-22661

CheckDescription
no-empty-passwordsDisable nullok in PAM system-auth and password-auth

Verified on OCP 5.0 (cnfdt16, RHCOS 10.2). authselect templates still ship with nullok. without-nullok feature not enabled by default. Upstream PRs (coreos/rhel-coreos-config#255, ComplianceAsCode/content#14602) still open.

H3: SSHD Empty Passwords — ✅ PASS (vanilla RHCOS 10.2+)

These checks PASS on vanilla RHCOS 10.2+ (OCP 5.0+) without MachineConfig remediation.

CheckDescription
sshd-disable-empty-passwordsPrevent SSH login with empty passwords

PermitEmptyPasswords is already set to 'no' by default in RHCOS 10.2 (OCP 5.0). No MachineConfig needed. OCP 4.22 and earlier still require remediation.

M1: SSHD Configuration — ✅ PASS (vanilla RHCOS 10.2+)

These checks PASS on vanilla RHCOS 10.2+ (OCP 5.0+) without MachineConfig remediation.

CheckDescription
sshd-disable-root-loginDisable direct root SSH access
sshd-disable-gssapi-authDisable GSSAPI authentication
sshd-disable-rhostsDisable rhost authentication
sshd-disable-user-known-hostsIgnore user's known_hosts file
sshd-do-not-permit-user-envBlock user environment variable passing
sshd-enable-strictmodesEnable strict mode checking
sshd-print-last-logDisplay last login information

All 7 SSHD settings (PermitRootLogin, GSSAPIAuthentication, IgnoreRhosts, etc.) are already set to hardened defaults in RHCOS 10.2 (OCP 5.0). No MachineConfig needed. OCP 4.22 and earlier still require remediation.

M2: Kernel Hardening (Sysctl) — ✅ PASS (vanilla RHCOS 10.2+)

These checks PASS on vanilla RHCOS 10.2+ (OCP 5.0+) without MachineConfig remediation.

CheckDescription
sysctl-kernel-randomize-va-spaceFull ASLR - randomizes memory layout
sysctl-kernel-unprivileged-bpf-disabledPrevent BPF-based privilege escalation
sysctl-kernel-yama-ptrace-scopeRestrict ptrace to parent-child processes
sysctl-net-core-bpf-jit-hardenHarden BPF JIT against spraying attacks

All 4 sysctl settings (randomize_va_space, unprivileged_bpf_disabled, bpf_jit_harden, yama.ptrace_scope) are set to desired values by default in RHCOS 10.2 (OCP 5.0). No MachineConfig needed. telco-reference PR #822 was reverted (PR #837). OCP 4.22 and earlier still require remediation.

M3: Audit Rules - DAC Modifications — 🟡 Pending
CheckDescription
audit-rules-dac-modification-chmodAudit DAC chmod
audit-rules-dac-modification-chownAudit DAC chown
M4: Audit Rules - SELinux — 🟡 Pending
CheckDescription
audit-rules-execution-chconAudit SELinux chcon
audit-rules-execution-restoreconAudit SELinux restorecon
audit-rules-execution-semanageAudit SELinux semanage
audit-rules-execution-setfilesAudit SELinux setfiles
audit-rules-execution-setseboolAudit SELinux setsebool
audit-rules-execution-seunshareAudit SELinux seunshare
M5: Audit Rules - Kernel Modules — 🟡 Pending
CheckDescription
audit-rules-kernel-module-loading-deleteAudit kernel module delete
audit-rules-kernel-module-loading-finitAudit kernel module finit
audit-rules-kernel-module-loading-initAudit kernel module init

Verified on OCP 5.0 (cnfdt16, RHCOS 10.2). Stock audit.rules has only basic buffer/backlog setup. No kernel module audit rules ship by default.

M6: Audit Rules - Time Modifications — 🟡 Pending
CheckDescription
audit-rules-time-adjtimexAudit time adjtimex
audit-rules-time-clock-settimeAudit time clock_settime
audit-rules-time-settimeofdayAudit time settimeofday
audit-rules-time-stimeAudit time stime
audit-rules-time-watch-localtimeAudit time localtime
M7: Audit Rules - Login Monitoring — 🟡 Pending
CheckDescription
audit-rules-login-events-faillockAudit login faillock
audit-rules-login-events-lastlogAudit login lastlog
audit-rules-login-events-tallylogAudit login tallylog
audit-rules-login-eventsAudit login events
audit-rules-sysadmin-actionsAudit sysadmin actions
audit-rules-usergroup-modificationAudit usergroup modification
M8: Audit Rules - Network Config — 🟡 Pending
CheckDescription
audit-rules-networkconfig-modificationAudit network config
M9: Auditd Configuration — 🟡 Pending
CheckDescription
auditd-name-formatAuditd name format

Verified on OCP 5.0 (cnfdt16, RHCOS 10.2). Stock auditd.conf has name_format=NONE (should be hostname), space_left=75 (should be 100), *_action=SUSPEND (should be syslog), q_depth=2000 (should be 400).

M10: API Server Encryption — 🟡 Pending
CheckDescription
api-server-encryption-provider-cipherAPI encryption

Verified on OCP 5.0 (cnfdt16, RHCOS 10.2). API encryption not enabled by default (generation:2 confirms manual application). Default install uses identity encryption.

M11: Ingress TLS Ciphers — ✅ PASS (vanilla RHCOS 10.2+)

These checks PASS on vanilla RHCOS 10.2+ (OCP 5.0+) without MachineConfig remediation.

CheckDescription
ingress-controller-tls-cipher-suitesIngress TLS ciphers

OCP 5.0 default IngressController TLS profile already meets CIS cipher suite requirements. No custom tlsSecurityProfile needed.

M12: Audit Profile — 🟡 Pending
CheckDescription
audit-profile-setAudit profile
L1: SSHD LogLevel — ✅ PASS (vanilla RHCOS 10.2+)

These checks PASS on vanilla RHCOS 10.2+ (OCP 5.0+) without MachineConfig remediation.

CheckDescription
sshd-set-loglevel-infoSet SSH logging to INFO level

SSHD LogLevel is already set to INFO by default in RHCOS 10.2 (OCP 5.0). No MachineConfig needed. OCP 4.22 and earlier still require remediation.

L2: Sysctl dmesg_restrict — 🟡 Pending
CheckDescription
sysctl-kernel-dmesg-restrictRestrict kernel log access to privileged users
M13: Extended DAC Audit — 🟡 Pending
CheckDescription
audit-rules-dac-modification-fchmodAudit fchmod operations
audit-rules-dac-modification-fchmodatAudit fchmodat operations
audit-rules-dac-modification-fchownAudit fchown operations
audit-rules-dac-modification-fchownatAudit fchownat operations
audit-rules-dac-modification-fremovexattrAudit fremovexattr operations
audit-rules-dac-modification-fsetxattrAudit fsetxattr operations
audit-rules-dac-modification-lchownAudit lchown operations
audit-rules-dac-modification-lremovexattrAudit lremovexattr operations
audit-rules-dac-modification-lsetxattrAudit lsetxattr operations
audit-rules-dac-modification-removexattrAudit removexattr operations
audit-rules-dac-modification-setxattrAudit setxattr operations
M14: Identity File Access Audit — 🟡 Pending
CheckDescription
audit-rules-etc-group-openAudit /etc/group access
audit-rules-etc-group-openatAudit /etc/group access via openat
audit-rules-etc-group-open-by-handle-atAudit /etc/group access via open_by_handle_at
audit-rules-etc-gshadow-openAudit /etc/gshadow access
audit-rules-etc-gshadow-openatAudit /etc/gshadow access via openat
audit-rules-etc-gshadow-open-by-handle-atAudit /etc/gshadow access via open_by_handle_at
audit-rules-etc-passwd-openAudit /etc/passwd access
audit-rules-etc-passwd-openatAudit /etc/passwd access via openat
audit-rules-etc-passwd-open-by-handle-atAudit /etc/passwd access via open_by_handle_at
audit-rules-etc-shadow-openAudit /etc/shadow access
audit-rules-etc-shadow-openatAudit /etc/shadow access via openat
audit-rules-etc-shadow-open-by-handle-atAudit /etc/shadow access via open_by_handle_at
M15: File Deletion Audit — 🟡 Pending
CheckDescription
audit-rules-file-deletion-events-renameAudit rename operations
audit-rules-file-deletion-events-renameatAudit renameat operations
audit-rules-file-deletion-events-rmdirAudit rmdir operations
audit-rules-file-deletion-events-unlinkAudit unlink operations
audit-rules-file-deletion-events-unlinkatAudit unlinkat operations
M16: Unsuccessful File Modification Audit — 🟡 Pending
CheckDescription
audit-rules-unsuccessful-file-modification-chmodAudit failed chmod
audit-rules-unsuccessful-file-modification-openAudit failed open
audit-rules-unsuccessful-file-modification-chownAudit failed chown
audit-rules-unsuccessful-file-modification-creatAudit failed creat
audit-rules-unsuccessful-file-modification-fchmodAudit failed fchmod
audit-rules-unsuccessful-file-modification-fchmodatAudit failed fchmodat
audit-rules-unsuccessful-file-modification-fchownAudit failed fchown
audit-rules-unsuccessful-file-modification-fchownatAudit failed fchownat
audit-rules-unsuccessful-file-modification-fremovexattrAudit failed fremovexattr
audit-rules-unsuccessful-file-modification-fsetxattrAudit failed fsetxattr
audit-rules-unsuccessful-file-modification-ftruncateAudit failed ftruncate
audit-rules-unsuccessful-file-modification-lchownAudit failed lchown
audit-rules-unsuccessful-file-modification-lremovexattrAudit failed lremovexattr
audit-rules-unsuccessful-file-modification-lsetxattrAudit failed lsetxattr
audit-rules-unsuccessful-file-modification-open-by-handle-atAudit failed open-by-handle-at
audit-rules-unsuccessful-file-modification-open-by-handle-at-o-creatAudit failed open-by-handle-at-o-creat
audit-rules-unsuccessful-file-modification-open-by-handle-at-o-trunc-writeAudit failed open-by-handle-at-o-trunc-write
audit-rules-unsuccessful-file-modification-open-by-handle-at-rule-orderAudit failed open-by-handle-at-rule-order
audit-rules-unsuccessful-file-modification-open-o-creatAudit failed open-o-creat
audit-rules-unsuccessful-file-modification-open-o-trunc-writeAudit failed open-o-trunc-write
audit-rules-unsuccessful-file-modification-open-rule-orderAudit failed open-rule-order
audit-rules-unsuccessful-file-modification-openatAudit failed openat
audit-rules-unsuccessful-file-modification-openat-o-creatAudit failed openat-o-creat
audit-rules-unsuccessful-file-modification-openat-o-trunc-writeAudit failed openat-o-trunc-write
audit-rules-unsuccessful-file-modification-openat-rule-orderAudit failed openat-rule-order
audit-rules-unsuccessful-file-modification-removexattrAudit failed removexattr
audit-rules-unsuccessful-file-modification-renameAudit failed rename
audit-rules-unsuccessful-file-modification-renameatAudit failed renameat
audit-rules-unsuccessful-file-modification-setxattrAudit failed setxattr
audit-rules-unsuccessful-file-modification-truncateAudit failed truncate
audit-rules-unsuccessful-file-modification-unlinkAudit failed unlink
audit-rules-unsuccessful-file-modification-unlinkatAudit failed unlinkat
M17: Privileged Commands Audit — 🟡 Pending
CheckDescription
audit-rules-privileged-commands-suAudit su execution
audit-rules-privileged-commands-sudoAudit sudo execution
audit-rules-privileged-commands-passwdAudit passwd execution
audit-rules-privileged-commands-mountAudit mount execution
audit-rules-privileged-commands-atAudit privileged at
audit-rules-privileged-commands-chageAudit privileged chage
audit-rules-privileged-commands-chshAudit privileged chsh
audit-rules-privileged-commands-crontabAudit privileged crontab
audit-rules-privileged-commands-gpasswdAudit privileged gpasswd
audit-rules-privileged-commands-newgidmapAudit privileged newgidmap
audit-rules-privileged-commands-newgrpAudit privileged newgrp
audit-rules-privileged-commands-newuidmapAudit privileged newuidmap
audit-rules-privileged-commands-pam-timestamp-checkAudit privileged pam-timestamp-check
audit-rules-privileged-commands-postdropAudit privileged postdrop
audit-rules-privileged-commands-postqueueAudit privileged postqueue
audit-rules-privileged-commands-pt-chownAudit privileged pt-chown
audit-rules-privileged-commands-ssh-keysignAudit privileged ssh-keysign
audit-rules-privileged-commands-sudoeditAudit privileged sudoedit
audit-rules-privileged-commands-umountAudit privileged umount
audit-rules-privileged-commands-unix-chkpwdAudit privileged unix-chkpwd
audit-rules-privileged-commands-userhelperAudit privileged userhelper
audit-rules-privileged-commands-usernetctlAudit privileged usernetctl
M18: Session & MAC Audit — 🟡 Pending
CheckDescription
audit-rules-session-eventsAudit session events
audit-rules-mac-modificationAudit MAC policy changes
audit-rules-media-exportAudit media export
audit-rules-immutableMake audit rules immutable
M19: Usergroup Modification Audit — 🟡 Pending
CheckDescription
audit-rules-usergroup-modification-groupWatch /etc/group
audit-rules-usergroup-modification-gshadowWatch /etc/gshadow
audit-rules-usergroup-modification-opasswdWatch /etc/opasswd
audit-rules-usergroup-modification-passwdWatch /etc/passwd
audit-rules-usergroup-modification-shadowWatch /etc/shadow
M20: Auditd Data Retention — 🟡 Pending
CheckDescription
auditd-data-disk-error-actionSet disk error action
auditd-data-disk-full-actionSet disk full action
auditd-data-retention-admin-space-left-actionSet admin space-left action
auditd-data-retention-space-leftSet space-left threshold
M21: Kernel Module Blacklist — 🟡 Pending

Jira: CNF-25994

CheckDescription
kernel-module-bluetooth-disabledDisable Bluetooth
kernel-module-usb-storage-disabledDisable USB storage
kernel-module-sctp-disabledDisable SCTP
kernel-module-atm-disabledDisable atm
kernel-module-can-disabledDisable can
kernel-module-cfg80211-disabledDisable cfg80211
kernel-module-cramfs-disabledDisable cramfs
kernel-module-firewire-core-disabledDisable firewire-core
kernel-module-freevxfs-disabledDisable freevxfs
kernel-module-hfs-disabledDisable hfs
kernel-module-hfsplus-disabledDisable hfsplus
kernel-module-iwlmvm-disabledDisable iwlmvm
kernel-module-iwlwifi-disabledDisable iwlwifi
kernel-module-jffs2-disabledDisable jffs2
kernel-module-mac80211-disabledDisable mac80211
kernel-module-squashfs-disabledDisable squashfs
kernel-module-tipc-disabledDisable tipc
kernel-module-udf-disabledDisable udf
M22: Network Sysctl Hardening — 🟡 Pending
CheckDescription
sysctl-net-ipv4-conf-all-accept-redirectsReject ICMP redirects
sysctl-net-ipv4-tcp-syncookiesEnable TCP SYN cookies
sysctl-net-ipv6-conf-all-accept-raReject IPv6 router advertisements
sysctl-net-ipv4-conf-all-accept-source-routeNet sysctl ipv4-conf-all-accept-source-route
sysctl-net-ipv4-conf-all-log-martiansNet sysctl ipv4-conf-all-log-martians
sysctl-net-ipv4-conf-all-rp-filterNet sysctl ipv4-conf-all-rp-filter
sysctl-net-ipv4-conf-all-secure-redirectsNet sysctl ipv4-conf-all-secure-redirects
sysctl-net-ipv4-conf-all-send-redirectsNet sysctl ipv4-conf-all-send-redirects
sysctl-net-ipv4-conf-default-accept-redirectsNet sysctl ipv4-conf-default-accept-redirects
sysctl-net-ipv4-conf-default-log-martiansNet sysctl ipv4-conf-default-log-martians
sysctl-net-ipv4-conf-default-rp-filterNet sysctl ipv4-conf-default-rp-filter
sysctl-net-ipv4-conf-default-secure-redirectsNet sysctl ipv4-conf-default-secure-redirects
sysctl-net-ipv4-conf-default-send-redirectsNet sysctl ipv4-conf-default-send-redirects
sysctl-net-ipv4-icmp-echo-ignore-broadcastsNet sysctl ipv4-icmp-echo-ignore-broadcasts
sysctl-net-ipv4-icmp-ignore-bogus-error-responsesNet sysctl ipv4-icmp-ignore-bogus-error-responses
sysctl-net-ipv6-conf-all-accept-redirectsNet sysctl ipv6-conf-all-accept-redirects
sysctl-net-ipv6-conf-all-accept-source-routeNet sysctl ipv6-conf-all-accept-source-route
sysctl-net-ipv6-conf-default-accept-raNet sysctl ipv6-conf-default-accept-ra
sysctl-net-ipv6-conf-default-accept-redirectsNet sysctl ipv6-conf-default-accept-redirects
sysctl-net-ipv6-conf-default-accept-source-routeNet sysctl ipv6-conf-default-accept-source-route
M23: Kernel Sysctl Extended — 🟡 Pending
CheckDescription
sysctl-kernel-kexec-load-disabledDisable kexec
sysctl-kernel-perf-event-paranoidRestrict perf_event
sysctl-kernel-core-patternDisable core dumps
M24: CoreOS Kernel Arguments — 🟡 Pending
CheckDescription
coreos-pti-kernel-argumentEnable PTI
coreos-audit-optionEnable audit
coreos-nousb-kernel-argumentDisable USB
coreos-audit-backlog-limit-kernel-argumentCoreOS kernel arg
coreos-page-poison-kernel-argumentCoreOS kernel arg
coreos-vsyscall-kernel-argumentCoreOS kernel arg
M25: Chrony/NTP Configuration — 🟡 Pending
CheckDescription
chronyd-client-onlyRestrict chrony to client mode
chronyd-no-chronyc-networkDisable chronyc network
chronyd-or-ntpd-set-maxpollChrony config
chronyd-or-ntpd-specify-multiple-serversChrony config
M26: Systemd Hardening — 🟡 Pending
CheckDescription
disable-ctrlaltdel-burstactionDisable Ctrl-Alt-Del burst
disable-ctrlaltdel-rebootDisable Ctrl-Alt-Del reboot
coredump-disable-backtracesDisable coredump backtraces
coredump-disable-storageDisable coredump storage
disable-users-coredumpsDisable user coredumps
service-systemd-coredump-disabledSystemd coredump disabled
M27: SSHD Moderate Extensions — 🟡 Pending
CheckDescription
sshd-set-idle-timeoutSet SSH idle timeout
sshd-set-keepaliveSet SSH keepalive
M28: USBGuard — 🟡 Pending
CheckDescription
package-usbguard-installedInstall USBGuard
service-usbguard-enabledEnable USBGuard
usbguard-allow-hid-and-hubAllow HID/hub USB devices
M29: System Access Controls — 🟡 Pending
CheckDescription
banner-etc-issueSet login banner
ensure-logrotate-activatedEnsure logrotate active
service-debug-shell-disabledDisable debug shell
no-tmux-in-shellsRestrict tmux in shells
banner-or-login-template-setLogin banner template
no-direct-root-loginsNo direct root logins
openshift-motd-existsMOTD configuration
M30: OAuth Configuration — 🟡 Pending
CheckDescription
oauth-or-oauthclient-inactivity-timeoutSet OAuth inactivity timeout
oauth-or-oauthclient-token-maxageSet OAuth token max age
MAN1: Workload Security — 🟡 Pending
CheckDescription
configure-network-policies-namespacesManual: Configure network policies per namespace
accounts-restrict-service-account-tokensManual: Restrict SA token automounting
accounts-unique-service-accountManual: Use unique service accounts
general-apply-sccManual: Apply SCCs to pods
general-default-namespace-useManual: Don't use default namespace
general-default-seccomp-profileManual: Enable seccomp profiles
general-namespaces-in-useManual: Use namespaces for isolation
scc-limit-privilege-escalationManual: Limit privilege escalation
scc-limit-privileged-containersManual: Limit privileged containers
scc-limit-root-containersManual: Limit root containers
scc-drop-container-capabilitiesManual: Drop container capabilities
scc-limit-container-allowed-capabilitiesManual: Limit container capabilities
scc-limit-ipc-namespaceManual: Limit IPC namespace
scc-limit-net-raw-capabilityManual: Limit NET_RAW
scc-limit-network-namespaceManual: Limit network namespace
scc-limit-process-id-namespaceManual: Limit PID namespace
general-configure-imagepolicywebhookManual: Image provenance
resource-requests-limits-in-daemonsetManual: Resource requests in daemonsets
resource-requests-quotaManual: Resource quotas
MAN2: RBAC & Access Control — 🟡 Pending
CheckDescription
rbac-least-privilegeManual: Review RBAC least privilege
rbac-limit-cluster-adminManual: Limit cluster-admin usage
rbac-limit-secrets-accessManual: Restrict secrets access
rbac-pod-creation-accessManual: Minimize pod creation access
rbac-wildcard-useManual: Minimize wildcard roles
idp-is-configuredManual: Configure identity provider
kubeadmin-removedManual: Remove kubeadmin
MAN3: Secrets Management — 🟡 Pending
CheckDescription
secrets-consider-external-storageManual: Use external secret storage
secrets-no-environment-variablesManual: Don't use env vars for secrets
MAN4: Audit Log Partitions — 🟡 Pending
CheckDescription
audit-log-forwarding-enabledManual: Audit log forwarding
audit-log-forwarding-uses-tlsManual: Audit log forwarding TLS
directory-access-var-log-auditManual: Audit log access
partition-for-var-logManual: /var/log partition
partition-for-var-log-auditManual: /var/log/audit partition
MAN5: Hardware/BIOS & Alerting — 🟡 Pending
CheckDescription
bios-disable-usb-bootManual: Disable USB boot
wireless-disable-in-biosManual: Disable WiFi in BIOS
acs-sensor-existsManual: ACS sensor deployment
cluster-version-operator-existsManual: CVO check
cluster-wide-proxy-setManual: Cluster proxy configuration
container-security-operator-existsManual: Container security operator
default-ingress-ca-replacedManual: Replace default ingress CA
enable-fips-modeManual: Enable FIPS mode
file-integrity-existsManual: File integrity operator
file-integrity-notification-enabledManual: File integrity notifications
fips-mode-enabled-on-all-nodesManual: FIPS on all nodes
ingress-controller-certificateManual: Ingress controller certificate
machine-volume-encryptedManual: Encrypt machine volumes
ocp-allowed-registriesManual: Configure allowed registries
ocp-allowed-registries-for-importManual: Allowed registries for import
security-profiles-operator-existsManual: Security profiles operator
alert-receiver-configuredManual: Configure alert receiver

Legend

Group Naming

Remediation Status

Upstream Verdict

Platform

Legend
Remediation Status
✅ PASS (vanilla) Passes on unhardened RHCOS; no remediation needed
🟢 Verified Remediation tested on live cluster, confirmed PASS
🔵 In Progress Remediation actively being developed or tested
🟡 Pending Not yet started; needs remediation work
🟠 Partial Some checks pass or remediation not fully validated
⚪ On Hold Work paused (blocked or deprioritized)
Upstream Verdict
🔼 Candidate Suitable for upstreaming to ComplianceAsCode
🟣 PR Open Upstream PR filed
🎯 RAN Only Only applies to RAN deployments
⚙️ Platform Requires OCP platform-level configuration
✅ Pass Already passing upstream
📍 Site Site/deployment-specific configuration
— N/A Not applicable for upstreaming
Platform
RHCOS Node-level checks (MachineConfig)
OCP Platform-level checks (API/CR)
Mixed Both RHCOS and OCP checks
Severity
HIGH
MEDIUM
LOW
MANUAL

Keyboard Shortcuts

Navigation
j / Next row
k / Previous row
Enter Open selected / Expand details
Esc Clear selection / Close modal
Actions
/ Focus search
d Toggle dark mode
? Show this help
g h Go to home
Filters
1 Show all
2 Pending only
3 In Progress only
4 Complete only