SlideShare ist ein Scribd-Unternehmen logo
1 von 47
Downloaden Sie, um offline zu lesen
Compliance, Security
Automation, and
Remediation with Red Hat
CloudForms, Red Hat Satellite,
and Ansible Tower by Red Hat
Lucy Huh Kerner
Senior Cloud Solutions Architect
Red Hat North America Public Sector
Matt Micene
Solutions Architect
DLT Solutions
GOAL
● Create a Security Compliant host at Provisioning time by 2 methods:
– Red Hat Satellite 6 + OpenSCAP
– Red Hat CloudForms + Red Hat Satellite + Ansible Tower by Red Hat
● Automate ongoing Security Remediation and Compliance with:
– Red Hat CloudForms + Red Hat Satellite + OpenSCAP
– Red Hat CloudForms + Ansible Tower by Red Hat
– Red Hat CloudForms Control/Policy Engine + Red Hat Insights
WHY AUTOMATE COMPLIANCE ?
Compliance, what's it good for?
CA DOJ recommends CIS Critical Security Controls as “minimum level
of information security” to meet standard of reasonableness
– California Breach Report https://oag.ca.gov/breachreport2016#findings
“Patch management and associated vulnerability management
processes represent the biggest problem areas, because they’re rarely
well documented and automated.”
– Anton Chuvakin [http://blogs.gartner.com/anton-chuvakin/2014/02/13/highlights-
from-verizon-pci-report-2014/]
Poster created by Ken Westin, 2015, used with permission of author. Hi
Ken!
WHAT IS SCAP?
SCAP = Security Content Automation Protocol (latest is version 1.2),
Specification: NIST SP 800-126 Rev. 2
● CCE™: Common Configuration Enumeration
● CPE™: Common Platform Enumeration
● CVE®: Common Vulnerabilities and Exposures
● CVSS: Common Vulnerability Scoring System
● CCSS: Common Configuration Scoring System
● XCCDF: The Extensible Configuration Checklist Description Format
● OVAL®: Open Vulnerability and Assessment Language
● OCIL: Open Checklist Interactive Language
● AI: Asset Identification
● ARF: Asset Reporting Format
WHAT IS OpenSCAP?
NIST validated SCAP scanner by Red Hat
https://nvd.nist.gov/scapproducts.cfm
METHOD #1:
Create a Security Compliant host at Provisioning time
with:
Red Hat Satellite 6 + OpenSCAP
Kickstarting SCAP
Create new Scan policy
Update scan host group
Create Kickstart templates
https://github.com/nzwulfin/rhsummit16-scap
Put it together in a new host
METHOD #2:
Create a Security Compliant host at Provisioning time
with:
Red Hat CloudForms + Red Hat Satellite + Ansible Tower
WHAT IS CLOUDFORMS?
Creating a Security Compliant host at Provisioning time with:
Red Hat CloudForms + Red Hat Satellite + Ansible Tower
Defense Information
Systems Agency Secure
Technical Implementation
Guide (DISA STIG)
CIS Security Benchmarks
ANSIBLE PLAYBOOK
ANSIBLE PLAYBOOK
Lauch the
CloudForms
Provisioning State
Machine
Post
Provisioning
Steps
WITH MULTI-
TENANCY !!!!
NO NEED TO WRITE
ANY CODE !!!!
DEMO
Automating ongoing Security Remediation and
Compliance with:
Red Hat CloudForms + Red Hat Satellite + OpenSCAP
Red Hat CloudForms + Ansible Tower by Red Hat
Red Hat CloudForms Control/Policy Engine + Red Hat Insights
Automated security scanning and remediation with :
Red Hat Satellite 5.7 + OpenSCAP + Red Hat CloudForms
OpenSCAP
XML-RPC
REST API
SCAN RESULTS:
PASS/FAIL
REMEDIATE
IF SCAN FAILS
Tag VM
(example:
scap_compliant: core_base_os
scap_noncompliant: top_secret)
XCCDF XML FILE with list of
security checks by Profile id
Create a Report based on scap_compliant
and scap_non compliant tags
Security remediations with Ansible Tower
using Red Hat CloudForms
DEMO
The Power and Flexibility of the Red Hat CloudForms
Control/Policy Engine
Managing Shell Shock compliance with Red Hat CloudForms Control
http://cloudformsblog.redhat.com/2014/09/28/shell-shock-bash-code-injection-vulnerability-via-specially-crafted-environment-variables-cve-2014-6271-cve-
2014-7169/#more-325
OpenSCAP compliance for Containers with Red Hat CloudForms Control
Proactive Systems Management with Red Hat Insights
SUMMARY
●Create a security compliant host at Provisioning time by 2 methods:
●Satellite 6 + OpenSCAP
●CloudForms + Satellite + Ansible Tower
●Automate ongoing security remediation and compliance with:
●CloudForms + Satellite + OpenSCAP
●CloudForms + Ansible Tower
●CloudForms Control/Policy Engine and Red Hat Insights
QUESTIONS ?
Matt Micene
Solutions Architect
DLT Solutions
matt.micene@dlt.com
Twitter: @cleverbeard
Lucy Huh Kerner
Senior Cloud Solutions Architect
Red Hat North America Public Sector
lkerner@redhat.com
Twitter: @LucyCloudBling
APPENDIX
●Example Satellite 6 provisioning templtae snippet and partition table
●https://github.com/nzwulfin/rhsummit16-scap
●Ansible playbooks for RHEL 6 CIS Benchmarks
●https://github.com/major/cis-rhel-ansible
●Ansible role for RHEL 6 DISA STIG from Ansible by Red Hat and
MindPointGroup
●https://github.com/ansible/ansible-lockdown
●https://github.com/MindPointGroup/RHEL6-STIG
SS42731_v2_KernerMicene

Weitere ähnliche Inhalte

Was ist angesagt?

OSDC 2016 - Hybrid Cloud - A Cloud Migration Strategy
OSDC 2016 - Hybrid Cloud - A Cloud Migration StrategyOSDC 2016 - Hybrid Cloud - A Cloud Migration Strategy
OSDC 2016 - Hybrid Cloud - A Cloud Migration Strategy
Schlomo Schapiro
 

Was ist angesagt? (20)

SOCstock 2021 The Cloud-native SOC
SOCstock 2021 The Cloud-native SOC SOCstock 2021 The Cloud-native SOC
SOCstock 2021 The Cloud-native SOC
 
OSDC 2016 - Hybrid Cloud - A Cloud Migration Strategy
OSDC 2016 - Hybrid Cloud - A Cloud Migration StrategyOSDC 2016 - Hybrid Cloud - A Cloud Migration Strategy
OSDC 2016 - Hybrid Cloud - A Cloud Migration Strategy
 
Why Cloud Management Makes Sense
Why Cloud Management Makes SenseWhy Cloud Management Makes Sense
Why Cloud Management Makes Sense
 
Cloud Native Applications Maturity Model
Cloud Native Applications Maturity ModelCloud Native Applications Maturity Model
Cloud Native Applications Maturity Model
 
RightScale Webinar: Successfully Deploy Your Windows Workloads
RightScale Webinar: Successfully Deploy Your Windows WorkloadsRightScale Webinar: Successfully Deploy Your Windows Workloads
RightScale Webinar: Successfully Deploy Your Windows Workloads
 
Event-Driven Serverless Architecture - the next big thing in the cloud (Cleme...
Event-Driven Serverless Architecture - the next big thing in the cloud (Cleme...Event-Driven Serverless Architecture - the next big thing in the cloud (Cleme...
Event-Driven Serverless Architecture - the next big thing in the cloud (Cleme...
 
Introducing rubrik a new approach to data protection
Introducing rubrik   a new approach to data protectionIntroducing rubrik   a new approach to data protection
Introducing rubrik a new approach to data protection
 
The good, the bad, and the ugly of migrating hundreds of legacy applications ...
The good, the bad, and the ugly of migrating hundreds of legacy applications ...The good, the bad, and the ugly of migrating hundreds of legacy applications ...
The good, the bad, and the ugly of migrating hundreds of legacy applications ...
 
Cloud Computing Design Considerations
Cloud Computing Design ConsiderationsCloud Computing Design Considerations
Cloud Computing Design Considerations
 
Oracle Xen Directions June09
Oracle Xen Directions June09Oracle Xen Directions June09
Oracle Xen Directions June09
 
Service Mesh: Two Big Words But Do You Need It?
Service Mesh: Two Big Words But Do You Need It?Service Mesh: Two Big Words But Do You Need It?
Service Mesh: Two Big Words But Do You Need It?
 
Monitoring a cloud native platform feature
Monitoring a cloud native platform featureMonitoring a cloud native platform feature
Monitoring a cloud native platform feature
 
Virtual Desktop Infrastructure with Novell Endpoint Management Solutions
Virtual Desktop Infrastructure with Novell Endpoint Management SolutionsVirtual Desktop Infrastructure with Novell Endpoint Management Solutions
Virtual Desktop Infrastructure with Novell Endpoint Management Solutions
 
F5 Automation Toolchain
F5 Automation ToolchainF5 Automation Toolchain
F5 Automation Toolchain
 
Dynamic Infrastructure and The Cloud
Dynamic Infrastructure and The CloudDynamic Infrastructure and The Cloud
Dynamic Infrastructure and The Cloud
 
[Event] Digital transformation : Enterprise cloud one os one click - PRESENTA...
[Event] Digital transformation : Enterprise cloud one os one click - PRESENTA...[Event] Digital transformation : Enterprise cloud one os one click - PRESENTA...
[Event] Digital transformation : Enterprise cloud one os one click - PRESENTA...
 
The Need of Cloud-Native Application
The Need of Cloud-Native ApplicationThe Need of Cloud-Native Application
The Need of Cloud-Native Application
 
How to Migrate to Cloud with Complete Confidence and Trust
How to Migrate to Cloud with Complete Confidence and TrustHow to Migrate to Cloud with Complete Confidence and Trust
How to Migrate to Cloud with Complete Confidence and Trust
 
Building a Global Multi-Tenant Monitoring Platform
Building a Global Multi-Tenant Monitoring PlatformBuilding a Global Multi-Tenant Monitoring Platform
Building a Global Multi-Tenant Monitoring Platform
 
Aws cloud migration simplified
Aws cloud migration simplifiedAws cloud migration simplified
Aws cloud migration simplified
 

Andere mochten auch

RHTE2015_CloudForms_Containers
RHTE2015_CloudForms_ContainersRHTE2015_CloudForms_Containers
RHTE2015_CloudForms_Containers
Jerome Marc
 
Red Hat OpenShift V3 Overview and Deep Dive
Red Hat OpenShift V3 Overview and Deep DiveRed Hat OpenShift V3 Overview and Deep Dive
Red Hat OpenShift V3 Overview and Deep Dive
Greg Hoelzer
 

Andere mochten auch (8)

Automating the Enterprise with CloudForms & Ansible
Automating the Enterprise with CloudForms & AnsibleAutomating the Enterprise with CloudForms & Ansible
Automating the Enterprise with CloudForms & Ansible
 
Integrate Openshift with Cloudforms
Integrate Openshift with CloudformsIntegrate Openshift with Cloudforms
Integrate Openshift with Cloudforms
 
RHTE2015_CloudForms_Containers
RHTE2015_CloudForms_ContainersRHTE2015_CloudForms_Containers
RHTE2015_CloudForms_Containers
 
Pedal to the metal: Red Hat CloudForms for workload & infrastructure management
Pedal to the metal: Red Hat CloudForms for workload & infrastructure managementPedal to the metal: Red Hat CloudForms for workload & infrastructure management
Pedal to the metal: Red Hat CloudForms for workload & infrastructure management
 
Red Hat OpenShift V3 Overview and Deep Dive
Red Hat OpenShift V3 Overview and Deep DiveRed Hat OpenShift V3 Overview and Deep Dive
Red Hat OpenShift V3 Overview and Deep Dive
 
Asterisk as a Virtual Network Function Part 1
Asterisk as a Virtual Network Function Part 1Asterisk as a Virtual Network Function Part 1
Asterisk as a Virtual Network Function Part 1
 
Managing open shift at scale across the open hybrid cloud
Managing open shift at scale across the open hybrid cloudManaging open shift at scale across the open hybrid cloud
Managing open shift at scale across the open hybrid cloud
 
Openstack Cloud Management and Automation Using Red Hat Cloudforms 4.0
Openstack Cloud  Management and Automation Using Red Hat Cloudforms 4.0Openstack Cloud  Management and Automation Using Red Hat Cloudforms 4.0
Openstack Cloud Management and Automation Using Red Hat Cloudforms 4.0
 

Ähnlich wie SS42731_v2_KernerMicene

What is this DevOps thing and why do I need it?
What is this DevOps thing and why do I need it?What is this DevOps thing and why do I need it?
What is this DevOps thing and why do I need it?
Safe Swiss Cloud
 
Maximice la flexibilidad estratégica creando una cloud hibrida y abierta
Maximice la flexibilidad estratégica creando una cloud hibrida y abiertaMaximice la flexibilidad estratégica creando una cloud hibrida y abierta
Maximice la flexibilidad estratégica creando una cloud hibrida y abierta
Nextel S.A.
 

Ähnlich wie SS42731_v2_KernerMicene (20)

Compliance Automation with InSpec
Compliance Automation with InSpecCompliance Automation with InSpec
Compliance Automation with InSpec
 
Button push deployments with integrated red hat open management
Button push deployments with integrated red hat open managementButton push deployments with integrated red hat open management
Button push deployments with integrated red hat open management
 
AnsibleFest 2020 - Automate cybersecurity solutions in a cloud native scenario
AnsibleFest 2020 - Automate cybersecurity solutions in a cloud native scenarioAnsibleFest 2020 - Automate cybersecurity solutions in a cloud native scenario
AnsibleFest 2020 - Automate cybersecurity solutions in a cloud native scenario
 
Create Secure Test and Dev Environments in the Cloud
Create Secure Test and Dev Environments in the CloudCreate Secure Test and Dev Environments in the Cloud
Create Secure Test and Dev Environments in the Cloud
 
Cncf checkov and bridgecrew
Cncf checkov and bridgecrewCncf checkov and bridgecrew
Cncf checkov and bridgecrew
 
Security and Advanced Automation in the Enterprise
Security and Advanced Automation in the EnterpriseSecurity and Advanced Automation in the Enterprise
Security and Advanced Automation in the Enterprise
 
What is this DevOps thing and why do I need it?
What is this DevOps thing and why do I need it?What is this DevOps thing and why do I need it?
What is this DevOps thing and why do I need it?
 
Dev ops
Dev opsDev ops
Dev ops
 
Connecting the Clouds - RightScale Compute 2013
Connecting the Clouds - RightScale Compute 2013Connecting the Clouds - RightScale Compute 2013
Connecting the Clouds - RightScale Compute 2013
 
Cluster-as-code. The Many Ways towards Kubernetes
Cluster-as-code. The Many Ways towards KubernetesCluster-as-code. The Many Ways towards Kubernetes
Cluster-as-code. The Many Ways towards Kubernetes
 
Pursuing evasive custom command & control - GuideM
Pursuing evasive custom command & control - GuideMPursuing evasive custom command & control - GuideM
Pursuing evasive custom command & control - GuideM
 
AWS Cloud Governance & Security through Automation - Atlanta AWS Builders
AWS Cloud Governance & Security through Automation - Atlanta AWS BuildersAWS Cloud Governance & Security through Automation - Atlanta AWS Builders
AWS Cloud Governance & Security through Automation - Atlanta AWS Builders
 
TENDENCIAS DE SEGURIDAD PARA AMBIENTES EN LA NUBE
TENDENCIAS DE SEGURIDAD PARA AMBIENTES EN LA NUBETENDENCIAS DE SEGURIDAD PARA AMBIENTES EN LA NUBE
TENDENCIAS DE SEGURIDAD PARA AMBIENTES EN LA NUBE
 
ansible_rhel_90.pdf
ansible_rhel_90.pdfansible_rhel_90.pdf
ansible_rhel_90.pdf
 
IBM Multicloud Management on the OpenShift Container Platform
IBM Multicloud Management on theOpenShift Container PlatformIBM Multicloud Management on theOpenShift Container Platform
IBM Multicloud Management on the OpenShift Container Platform
 
2011-08-10 In-Q-Tel Technology Focus Day, Trends & Observations in Open Sourc...
2011-08-10 In-Q-Tel Technology Focus Day, Trends & Observations in Open Sourc...2011-08-10 In-Q-Tel Technology Focus Day, Trends & Observations in Open Sourc...
2011-08-10 In-Q-Tel Technology Focus Day, Trends & Observations in Open Sourc...
 
Cloud Computing and Security - by KLC Consulting
Cloud Computing and Security - by KLC ConsultingCloud Computing and Security - by KLC Consulting
Cloud Computing and Security - by KLC Consulting
 
Building and Adopting a Cloud-Native Security Program
Building and Adopting a Cloud-Native Security ProgramBuilding and Adopting a Cloud-Native Security Program
Building and Adopting a Cloud-Native Security Program
 
Maximice la flexibilidad estratégica creando una cloud hibrida y abierta
Maximice la flexibilidad estratégica creando una cloud hibrida y abiertaMaximice la flexibilidad estratégica creando una cloud hibrida y abierta
Maximice la flexibilidad estratégica creando una cloud hibrida y abierta
 
Monitoring CloudStack and components
Monitoring CloudStack and componentsMonitoring CloudStack and components
Monitoring CloudStack and components
 

SS42731_v2_KernerMicene

  • 1. Compliance, Security Automation, and Remediation with Red Hat CloudForms, Red Hat Satellite, and Ansible Tower by Red Hat Lucy Huh Kerner Senior Cloud Solutions Architect Red Hat North America Public Sector Matt Micene Solutions Architect DLT Solutions
  • 2. GOAL ● Create a Security Compliant host at Provisioning time by 2 methods: – Red Hat Satellite 6 + OpenSCAP – Red Hat CloudForms + Red Hat Satellite + Ansible Tower by Red Hat ● Automate ongoing Security Remediation and Compliance with: – Red Hat CloudForms + Red Hat Satellite + OpenSCAP – Red Hat CloudForms + Ansible Tower by Red Hat – Red Hat CloudForms Control/Policy Engine + Red Hat Insights
  • 4. Compliance, what's it good for? CA DOJ recommends CIS Critical Security Controls as “minimum level of information security” to meet standard of reasonableness – California Breach Report https://oag.ca.gov/breachreport2016#findings “Patch management and associated vulnerability management processes represent the biggest problem areas, because they’re rarely well documented and automated.” – Anton Chuvakin [http://blogs.gartner.com/anton-chuvakin/2014/02/13/highlights- from-verizon-pci-report-2014/]
  • 5. Poster created by Ken Westin, 2015, used with permission of author. Hi Ken!
  • 6. WHAT IS SCAP? SCAP = Security Content Automation Protocol (latest is version 1.2), Specification: NIST SP 800-126 Rev. 2 ● CCE™: Common Configuration Enumeration ● CPE™: Common Platform Enumeration ● CVE®: Common Vulnerabilities and Exposures ● CVSS: Common Vulnerability Scoring System ● CCSS: Common Configuration Scoring System ● XCCDF: The Extensible Configuration Checklist Description Format ● OVAL®: Open Vulnerability and Assessment Language ● OCIL: Open Checklist Interactive Language ● AI: Asset Identification ● ARF: Asset Reporting Format
  • 7. WHAT IS OpenSCAP? NIST validated SCAP scanner by Red Hat https://nvd.nist.gov/scapproducts.cfm
  • 8. METHOD #1: Create a Security Compliant host at Provisioning time with: Red Hat Satellite 6 + OpenSCAP
  • 10.
  • 11.
  • 12.
  • 13.
  • 14. Create new Scan policy
  • 15.
  • 16.
  • 17.
  • 18.
  • 20.
  • 21.
  • 24.
  • 25.
  • 26. Put it together in a new host
  • 27.
  • 28.
  • 29.
  • 30.
  • 31. METHOD #2: Create a Security Compliant host at Provisioning time with: Red Hat CloudForms + Red Hat Satellite + Ansible Tower
  • 33. Creating a Security Compliant host at Provisioning time with: Red Hat CloudForms + Red Hat Satellite + Ansible Tower Defense Information Systems Agency Secure Technical Implementation Guide (DISA STIG) CIS Security Benchmarks ANSIBLE PLAYBOOK ANSIBLE PLAYBOOK Lauch the CloudForms Provisioning State Machine Post Provisioning Steps WITH MULTI- TENANCY !!!! NO NEED TO WRITE ANY CODE !!!!
  • 34. DEMO
  • 35. Automating ongoing Security Remediation and Compliance with: Red Hat CloudForms + Red Hat Satellite + OpenSCAP Red Hat CloudForms + Ansible Tower by Red Hat Red Hat CloudForms Control/Policy Engine + Red Hat Insights
  • 36. Automated security scanning and remediation with : Red Hat Satellite 5.7 + OpenSCAP + Red Hat CloudForms OpenSCAP XML-RPC REST API SCAN RESULTS: PASS/FAIL REMEDIATE IF SCAN FAILS Tag VM (example: scap_compliant: core_base_os scap_noncompliant: top_secret) XCCDF XML FILE with list of security checks by Profile id Create a Report based on scap_compliant and scap_non compliant tags
  • 37. Security remediations with Ansible Tower using Red Hat CloudForms
  • 38. DEMO
  • 39. The Power and Flexibility of the Red Hat CloudForms Control/Policy Engine
  • 40. Managing Shell Shock compliance with Red Hat CloudForms Control http://cloudformsblog.redhat.com/2014/09/28/shell-shock-bash-code-injection-vulnerability-via-specially-crafted-environment-variables-cve-2014-6271-cve- 2014-7169/#more-325
  • 41. OpenSCAP compliance for Containers with Red Hat CloudForms Control
  • 42. Proactive Systems Management with Red Hat Insights
  • 43. SUMMARY ●Create a security compliant host at Provisioning time by 2 methods: ●Satellite 6 + OpenSCAP ●CloudForms + Satellite + Ansible Tower ●Automate ongoing security remediation and compliance with: ●CloudForms + Satellite + OpenSCAP ●CloudForms + Ansible Tower ●CloudForms Control/Policy Engine and Red Hat Insights
  • 44.
  • 45. QUESTIONS ? Matt Micene Solutions Architect DLT Solutions matt.micene@dlt.com Twitter: @cleverbeard Lucy Huh Kerner Senior Cloud Solutions Architect Red Hat North America Public Sector lkerner@redhat.com Twitter: @LucyCloudBling
  • 46. APPENDIX ●Example Satellite 6 provisioning templtae snippet and partition table ●https://github.com/nzwulfin/rhsummit16-scap ●Ansible playbooks for RHEL 6 CIS Benchmarks ●https://github.com/major/cis-rhel-ansible ●Ansible role for RHEL 6 DISA STIG from Ansible by Red Hat and MindPointGroup ●https://github.com/ansible/ansible-lockdown ●https://github.com/MindPointGroup/RHEL6-STIG