Compliance Management
Forge provides comprehensive compliance management capabilities, supporting multiple compliance frameworks and automated remediation.
Overview
Forge's compliance features help you:
- Import Compliance Frameworks - STIG, CIS, NIST, PCI-DSS
- Track Findings - Manage compliance findings and their status
- Automate Remediation - Use Policy Packs and task templates
- Monitor Coverage - Track automated vs manual remediation
- Export Reports - Generate CKL files and compliance reports
- Scan Systems - Use OpenSCAP for automated compliance scanning
Key Features
STIG Compliance
- Import STIG checklists (CKL files)
- Interactive STIG Viewer for finding management
- Policy Packs for automated remediation
- Manual task assignment for bulk operations
- CKL export for certification
OpenSCAP Compliance
- Upload SCAP DataStream files
- Create compliance policies
- Schedule automated scans
- View detailed compliance reports
- Download ARF files for analysis
Compliance Frameworks
- Support for multiple frameworks per project
- Framework-specific workflows
- Compliance dashboard
- Historical tracking
Quick Start
1. Import a STIG Checklist
- Navigate to Compliance > Frameworks
- Click Import Framework
- Upload your
.cklfile - Select a Policy Pack (optional)
- Review imported findings
2. Install a Policy Pack
- Navigate to Compliance > Policy Pack Library
- Browse available packs
- Click Install Pack
- Remediation tasks are automatically linked
3. Assign Remediation Templates
- Navigate to Compliance > Remediation Coverage
- Filter to show "Manual" findings
- Click Assign Template
- Select a remediation template
- Review and execute assignment
4. Run Remediation Tasks
- Navigate to Task Templates
- Find remediation templates
- Click Run to execute
- Monitor task progress
- Update finding status in STIG Viewer
Workflow Examples
STIG Hardening Workflow
- Import STIG - Upload CKL file for your system
- Install Policy Pack - Get automated remediation tasks
- Review Findings - Use STIG Viewer to assess status
- Assign Templates - Link manual findings to tasks
- Run Remediation - Execute automated fixes
- Verify Compliance - Re-scan or manually verify
- Export CKL - Generate updated checklist for certification
OpenSCAP Scanning Workflow
- Upload SCAP Content - Add DataStream files
- Create Policy - Define scan policy and profile
- Assign Targets - Select inventories or hosts
- Schedule Scans - Set up periodic scanning
- Review Reports - Analyze compliance results
- Remediate Issues - Create tasks for findings
- Track Progress - Monitor compliance over time
Best Practices
Organization
- Use separate projects for different compliance frameworks
- Tag findings with environment (dev, staging, prod)
- Document exceptions and waivers
- Maintain audit trails
Automation
- Install Policy Packs for common remediations
- Use bulk assignment for manual findings
- Schedule regular compliance scans
- Automate remediation where possible
Reporting
- Export CKL files regularly for certification
- Maintain compliance dashboards
- Track remediation coverage percentage
- Document manual review processes
Related Documentation
- STIG Compliance - Detailed STIG workflow
- OpenSCAP Compliance - SCAP-based scanning
- Policy Packs - Automated remediation
- Remediation Coverage - Tracking automation
- Golden Images - STIG-hardened images