Skip to content

chore: separates rhel nist-800-53 artifacts by group - #55

Draft
hbraswelrh wants to merge 3 commits into
complytime:mainfrom
hbraswelrh:chore/updates-rhel-nist-800-53
Draft

chore: separates rhel nist-800-53 artifacts by group#55
hbraswelrh wants to merge 3 commits into
complytime:mainfrom
hbraswelrh:chore/updates-rhel-nist-800-53

Conversation

@hbraswelrh

Copy link
Copy Markdown
Member

Summary

This PR splits up the ControlCatalogs introduced in PR #53 by group (i.e., control family) proposing a condensed sub-set with a reduced line count per single ControlCatalog file. There were no content changes made, only shaping and line count.

Previously the assessment-requirements in the ControlCatalogs were using pointers to reference the applicability-groups values (e.g., applicability: *001 where &001 is fedora-*). The approach works properly. However, for ease of maintainability, the applicability-groups should be fully expanded for readability. This should also help with identification of assessment-requirements and associated applicability.

Related Issues

Inform any issues relevant to this PR. For example:

Review Hints

ggbecker and others added 3 commits July 30, 2026 17:25
Adds Gemara-compliant artifacts for NIST SP 800-53 Revision 5 compliance
evaluation on Fedora systems.

Source: ComplianceAsCode/content
Branch: add-nist-800-53-fedora-control
Testing: Validated with Complytime scan on Fedora 39

Artifacts:
- Bundle manifest (3 layers)
- Control catalog (1,196 controls, 439 rules, 539 mappings)
- Policy (439 assessment plans with OpenSCAP evaluation)

Scan results: 17 requirements tested (9 passed, 8 failed)
Controls verified: AC, AU, IA, SC, SI families

This PR complements the RHEL artifacts and enables Complytime
compliance scanning for Fedora distributions.
Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Hannah Braswell <hbraswel@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants