InSpec compliance profile for checking Linux hardening baseline settings
- Stars874
- Forks193
- Open Issues20
Apache-2.0
- Ruby

About DevSec Linux Baseline
DevSec Linux Baseline is an InSpec compliance profile that checks Linux security baseline settings. It gives teams a repeatable, automated way to confirm that a host actually meets a hardening baseline rather than trusting that earlier hardening still holds.
It runs under InSpec, either from a local clone or straight from its source URL, and reports each control as pass or fail. The focus is verification, not configuration, so it slots cleanly into audit and compliance pipelines and complements tools that do the hardening.
Running it regularly catches configuration drift across a fleet, keeping every system measured against the same expected baseline. It is part of the DevSec Hardening Framework and released under the Apache 2.0 license.
Key features
- Audits Linux hardening baselines with InSpec
- Reports each control as pass or fail
- Runs from a local clone or its source URL
- Catches configuration drift across a fleet
Details
- On GitHub since
- 2014
- License
- Apache-2.0
- Platforms
- Linux · CLI
- Type
- InSpec compliance profile
- Maintainer
- DevSec Hardening Framework
- Language
- Ruby
