From c4b41d25aa32a2fba67768b95c11b6cd1bd0efb5 Mon Sep 17 00:00:00 2001 From: Edgar Aguilar Date: Tue, 4 Oct 2022 18:23:01 -0500 Subject: [PATCH] Introduce cui profile for OL9 Signed-off-by: Edgar Aguilar --- products/ol9/profiles/cui.profile | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 products/ol9/profiles/cui.profile diff --git a/products/ol9/profiles/cui.profile b/products/ol9/profiles/cui.profile new file mode 100644 index 00000000000..abb37b457a8 --- /dev/null +++ b/products/ol9/profiles/cui.profile @@ -0,0 +1,30 @@ +documentation_complete: true + +metadata: + version: TBD + +title: '[DRAFT] Unclassified Information in Non-federal Information Systems and Organizations (NIST 800-171)' + +description: |- + From NIST 800-171, Section 2.2: + Security requirements for protecting the confidentiality of CUI in nonfederal + information systems and organizations have a well-defined structure that + consists of: + + (i) a basic security requirements section; + (ii) a derived security requirements section. + + The basic security requirements are obtained from FIPS Publication 200, which + provides the high-level and fundamental security requirements for federal + information and information systems. The derived security requirements, which + supplement the basic security requirements, are taken from the security controls + in NIST Special Publication 800-53. + + This profile configures Oracle Linux 9 to the NIST Special + Publication 800-53 controls identified for securing Controlled Unclassified + Information (CUI)." + +extends: ospp + +selections: + - inactivity_timeout_value=10_minutes