-
Notifications
You must be signed in to change notification settings - Fork 144
Security:2021 Till Dec Roadmap
Status: PLANNED
This is an uncommitted roadmap for 2021 until December (some things might get dropped or added over the period).
Feedback welcome in #ansible-security
on IRC Libera.chat.
Cisco ASA, IBM Qradar, Splunk ES, Trendmicro Deepsecurity, Symantec EPM.
1. Update existing Ansible Security supported collection to use resource modules design and support the states associated with resource module:
- Merged
- Replaced
- Overridden
- Deleted
- Gathered
Once available, the tool will assist developers from both the community and the vendor team in simply building integrations with Ansible, with the newer resource module architecture, and all of the best practices that are taken into account when designing an integrated Ansible module.
We'll be updating the existing Ansible supported security roles to include the support for all of the certified security platforms/vendors Ansible Security supports, available Ansible supported security roles:
We've begun collaborating with Kubernetes and Container security platforms and vendors to provide an Ansible integration solution for automating Kubernetes and Container security use cases.
StackRox will be the first platform to launch in the space.
Firewall policy automation
- Dynamic documentation and reporting
- Identify policy misconfigurations
- Policy visibility informs the policy misconfiguration remediation plan
- Collect and provide current firewall policy configurations in a human-readable format using facts. Teams can use this data to create a remediation plan to address configuration debt and desired state definitions.
- Teams can then implement desired-state firewall policy definitions across regions and multi-vendor environments.
- Ensure firewall policies remain optimized and enforced.
- Firewall practitioners can compare current and desired states to identify drift.
Modules roadmap
- log_source_management -adding, deleting, modifying log sources
- event_info - obtain information about one or many SIEM events, with filter options
- event_action - assign, protect, follow up, set status, and assign closing reason to a SIEM event
- event_enrich - create or update a SIEM event note/workbench entry
- rule - adding, deleting, modifying SIEM correlation rules, with filter options
- rule_info - obtain information about one or many SIEM correlation rules, with filter options
Additional platforms
- Exabeam
- Securonix
- LogRhythm
- Rapid7
Modules roadmap
- account - Adding, deleting, modifying a privileged credential
- authentication - Authenticate using PAS services
- credential - retrieving a credential from an object
- user - PAM user management (e.g. Get User Details, Add User, Update User, Delete User)
Additional platforms
- Thycotic
- BeyondTrust
- Centrify
Modules roadmap
- security_policy - Configure new security policies
- apikey - Configure API Keys.
- firewall_rule - Configure firewall rules
- hosts_info - Obtain information about one or many hosts under EDR protection
- log_inspection_rule - Configure log inspection rules
- syslog - Configure syslog configuration
- system_settings - Configure EDR system settings
Additional platforms
- Microsoft Defender ATP
- McAfee Endpoint Protection
- Sophos
- SentinelOne
- CrowdStrike
Additional platforms
- Palo Alto Networks Prisma Cloud Compute Edition
- Aqua Security
- Anchore
This Wiki is used for quick notes, not for support or documentation.
Working groups are now in the Ansible forum
Ansible project:
Community,
Contributor Experience,
Docs,
News,
Outreach,
RelEng,
Testing
Cloud:
AWS,
Azure,
CloudStack,
Container,
DigitalOcean,
Docker,
hcloud,
Kubernetes,
Linode,
OpenStack,
oVirt,
Virt,
VMware
Networking:
ACI,
AVI,
F5,
Meraki,
Network,
NXOS
Ansible Developer Tools:
Ansible-developer-tools
Software:
Crypto,
Foreman,
GDrive,
GitLab,
Grafana,
IPA,
JBoss,
MongoDB,
MySQL,
PostgreSQL,
RabbitMQ,
Zabbix
System:
AIX,
BSD,
HP-UX,
macOS,
Remote Management,
Solaris,
Windows
Security:
Security-Automation,
Lockdown
Tooling:
AWX,
Galaxy,
Molecule
Plugins:
httpapi