OCP 5.1 Remediation Groups

← Back to OCP 5.1 Compliance Status View Summary

Each group below represents a logical set of related compliance checks that can be remediated together in a single MachineConfig or CRD.


HIGH Severity

Group Title Priority Status Jira PR
H1 Crypto Policy P1 🟡 Pending - -
H2 PAM Empty Passwords P1 🟡 Pending - -
H3 SSHD Empty Passwords P1 🟡 Pending - -

MEDIUM Severity

Group Title Priority Status Compare Jira PR
M1 SSHD Configuration P2 🟡 Pending - - -
M2 Kernel Hardening (Sysctl) P3 🟡 Pending - - -
M3 Audit Rules - DAC Modifications P3 🟡 Pending 📦 - -
M4 Audit Rules - SELinux P2 🟡 Pending 📦 - -
M5 Audit Rules - Kernel Modules P3 🟡 Pending 📦 - -
M6 Audit Rules - Time Modifications P2 🟡 Pending 📦 - -
M7 Audit Rules - Login Monitoring P2 🟡 Pending 📦 - -
M8 Audit Rules - Network Config P3 🟡 Pending 📦 - -
M9 Auditd Configuration P3 🟡 Pending 📦 - -
M10 API Server Encryption P2 🟡 Pending 📦 - -
M11 Ingress TLS Ciphers P3 🟡 Pending - - -
M12 Audit Profile P3 🟡 Pending 📦 - -
M13 Extended DAC Audit P3 🟡 Pending 📦 - -
M14 Identity File Access Audit P3 🟡 Pending 📦 - -
M15 File Deletion Audit P3 🟡 Pending 📦 - -
M16 Unsuccessful File Modification Audit P3 🟡 Pending 📦 - -
M17 Privileged Commands Audit P3 🟡 Pending 📦 - -
M18 Session & MAC Audit P3 🟡 Pending 📦 - -
M19 Usergroup Modification Audit P3 🟡 Pending 📦 - -
M20 Auditd Data Retention P3 🟡 Pending 📦 - -
M21 Kernel Module Blacklist P3 🟡 Pending 📦 - -
M22 Network Sysctl Hardening P3 🟡 Pending 📦 - -
M23 Kernel Sysctl Extended P3 🟡 Pending 📦 - -
M24 CoreOS Kernel Arguments P3 🟡 Pending 📦 - -
M25 Chrony/NTP Configuration P3 🟡 Pending 📦 - -
M26 Systemd Hardening P3 🟡 Pending 📦 - -
M27 SSHD Moderate Extensions P3 🟡 Pending 📦 - -
M28 USBGuard P3 🟡 Pending 📦 - -
M29 System Access Controls P3 🟡 Pending 📦 - -
M30 OAuth Configuration P3 🟡 Pending 📦 - -

LOW Severity

Group Title Priority Status Compare Jira PR
L1 SSHD LogLevel P4 🟡 Pending - - -
L2 Sysctl dmesg_restrict P4 🟡 Pending 📦 - -

Manual Checks (No Auto-Remediation)

These checks require manual operator review — no MachineConfig or CRD can fix them automatically.

Group Title Priority Status
MAN1 Workload Security P3 🟡 Pending
MAN2 RBAC & Access Control P2 🟡 Pending
MAN3 Secrets Management P3 🟡 Pending
MAN4 Audit Log Partitions P4 🟡 Pending
MAN5 Hardware/BIOS & Alerting P4 🟡 Pending

Group Naming Convention

Priority Legend

Priority Label Criteria
P1 Critical HIGH severity - security critical
P2 High MEDIUM severity with high impact (5+ checks) or API/encryption
P3 Medium MEDIUM severity with standard impact
P4 Low LOW severity - best practices
P5 Deferred On hold or blocked

Status Legend

Status Meaning
✅ PASS (vanilla) Passes on unhardened RHCOS; no remediation needed
🟢 Verified Remediation tested on live cluster, confirmed PASS
🔵 In Progress Remediation actively being developed or tested
🟡 Pending Not yet started; needs remediation work
🟠 Partial Some checks pass or remediation not fully validated
⚪ On Hold Work paused (blocked or deprioritized)

Linking to Groups from PRs

Use these URLs in your PR descriptions:

https://sebrandon1.github.io/compliance-scripts/versions/5.1/groups/H1.html
https://sebrandon1.github.io/compliance-scripts/versions/5.1/groups/M1.html

Example markdown for PR descriptions:

This PR implements [H1: Crypto Policy](https://sebrandon1.github.io/compliance-scripts/versions/5.1/groups/H1.html) and [H2: PAM Empty Passwords](https://sebrandon1.github.io/compliance-scripts/versions/5.1/groups/H2.html).
Legend
Remediation Status
✅ PASS (vanilla) Passes on unhardened RHCOS; no remediation needed
🟢 Verified Remediation tested on live cluster, confirmed PASS
🔵 In Progress Remediation actively being developed or tested
🟡 Pending Not yet started; needs remediation work
🟠 Partial Some checks pass or remediation not fully validated
⚪ On Hold Work paused (blocked or deprioritized)
Upstream Verdict
🔼 Candidate Suitable for upstreaming to ComplianceAsCode
🟣 PR Open Upstream PR filed
🎯 RAN Only Only applies to RAN deployments
⚙️ Platform Requires OCP platform-level configuration
✅ Pass Already passing upstream
📍 Site Site/deployment-specific configuration
— N/A Not applicable for upstreaming
Platform
RHCOS Node-level checks (MachineConfig)
OCP Platform-level checks (API/CR)
Mixed Both RHCOS and OCP checks
Severity
HIGH
MEDIUM
LOW
MANUAL