Configuring CEM
Configuration of CEM is optional. If you
installed CEM and assigned the cem_linux
class to one or more node groups, the Center for Internet Security (CIS) Server Level 1
profile is enforced automatically during the next Puppet
run. However, if the default values leave your infrastructure in an undesirable state, or if
you want to customize compliance to meet your organization's requirements, you can configure
CEM.
For example, if a CIS control sets the maximum password age at 365 days, but your organization requires a password change every 90 days, you can configure CEM accordingly.
You must also configure CEM if you plan to enforce DISA STIG standards rather than a CIS Benchmark. Follow the instructions in Configure DISA STIG.
For all types of configuration tasks, you can use the Hiera key-value store in your control repository. For more information, see About Hiera and Getting started with Hiera.
For general information about CEM configuration options, see Overview of configuration options. For detailed information about CEM configuration options, see the CEM Linux Reference.
For configuration examples, see How to configure the module: Examples and guidelines.
-
Overview of configuration options
Configuration options include top-level options, benchmark options, and Center for Internet Security (CIS)-specific options. -
How to configure the module: Examples and guidelines
Configuration examples are provided to help you understand how CEM is used in a production environment. Guidelines are provided to help optimize your configuration.