馃攧 NIST 800-53 CIS Reference Update (2026-09-13) - #15121
Conversation
This automated update regenerates the CIS鈫扤IST reference file from the latest OSCAL catalog and CIS benchmark mappings. Changes: +0/-3 lines in CIS reference files鈿狅笍 MANUAL ACTION REQUIRED: Review the diff and manually update the product control files. Generated by: Weekly NIST 800-53 Sync Workflow Co-Authored-By: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Detailed Changes in CIS Reference FilesChanged Family Files馃搧 Family files diffTip: Family files (ac.yml, au.yml, cm.yml, etc.) make it |
|
Hi @github-actions[bot]. Thanks for your PR. I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/ok-to-test |
|
All PipelineRuns for this commit have already succeeded. Use |
|
/retest |
|
All PipelineRuns for this commit have already succeeded. Use |
|
/test |
This comment was marked as outdated.
This comment was marked as outdated.
|
@github-actions[bot]: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
馃攧 Workflow Re-run Update The CIS-NIST sync workflow ran again at 2026-09-20 14:17:32 UTC. Automated comment from workflow run 35515937614 |
ggbecker
left a comment
There was a problem hiding this comment.
No additional changes are needed in the product-specific RHEL 9 NIST control files.
The three rules removed by this PR:
file_owner_at_allowfromAC-3group_unique_namefromCM-1file_ownership_home_directoriesfromCM-6
were already removed from products/rhel9/controls/nist_800_53/ in commit 0c013cc7de.
This was done to keep the RHEL 9 NIST mappings consistent with the RHEL 9 CIS profile, which explicitly excludes these rules. PR #15121 only removes the corresponding stale entries from the generated shared CIS-to-NIST reference files.
Therefore, applying additional changes to the RHEL 9 NIST control files would produce no diff. The RHEL 8 and RHEL 10 mappings remain unchanged because this exclusion is specific to RHEL 9.
Summary
This automated PR updates the CIS reference file showing the
latest CIS鈫扤IST mappings.
Review changes and update product control files accordingly:
products/{p}/controls/nist_800_53/*.ymlChanges
shared/references/controls/File Roles
shared/references/.../{p}.ymlshared/references/.../{p}/*.ymlproducts/{p}/controls/nist_800_53.ymlproducts/{p}/controls/nist_800_53/*.ymlDetails
馃 Generated by weekly sync workflow