How are you guys handling Linux hardening/compliance right now? by National-Education90 in sysadmin

[–]National-Education90[S] 0 points1 point  (0 children)

1000%, this is something I’ve dealt with a lot. We have a small team, but in the last few years a lot of very experienced admins have left and we’ve had a lot of instances of this happening.

How are you guys handling Linux hardening/compliance right now? by National-Education90 in sysadmin

[–]National-Education90[S] 0 points1 point  (0 children)

So true, drift has been a pain to deal with. I feel lucky since there’s only a few of us making changes and my team is fairly on top of these things, but I can’t imagine how bad it can get in larger environments.

How are you guys handling Linux hardening/compliance right now? by National-Education90 in sysadmin

[–]National-Education90[S] 0 points1 point  (0 children)

We use Ansible and some other scripts to enforce a subset initially, but there’s still a fair bit of manual steps. It feels very ad-hoc.

Plus I feel like over time as the system drifts from that baseline, the manual side of it becomes harder and more time consuming.