Report Score API Endpoint for Automation

1 votes

In a mature state of using the CIS toolset:
1. CIS CAT Pro (CCP) Assessor is automated to scan a given system after changes are made to that system. The scan results are uploaded to CIS Secure Suite via API. The scan results is typically less than 100% at this stage because CCP Assessor lacks the knowledge of the known exceptions.
2. CIS Secure Suite manages all the exceptions for the targets being scanned by CCP Assessor. If no new misconfigurations are introduced, then compliance will be 100%.
3. Right now, a human is required to manually login to CIS Secure Suite and verify that compliance score of the scan is 100%. In a more automated and mature state, the report score (including known exceptions) verification should be available via an API. This new API endpoint would allow for automation in CI/CD pipelines and remove the need for an individual login to CIS Secure Suite to verify if the score is still 100%.

Thanks in advance and please reach out if you have more questions.

Under consideration Suggested by: Noor S Upvoted: 26 Jan Comments: 0

Comments: 0