Skip to content

馃攧 NIST 800-53 CIS Reference Update (2026-09-13) - #15121

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
auto-update-nist-800-53-20260913-141741
Open

github-actions[bot] wants to merge 1 commit into
masterfrom
auto-update-nist-800-53-20260913-141741

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Summary

This automated PR updates the CIS reference file showing the
latest CIS鈫扤IST mappings.

鈿狅笍 MANUAL ACTION REQUIRED

Review changes and update product control files accordingly:

  1. Review the diff to see what changed in CIS mappings
  2. Apply changes to products/{p}/controls/nist_800_53/*.yml
  3. Preserve human-added rules or notes in the real files
  4. Commit manual updates to the real control files in this PR

Changes

  • +0/-3 lines modified in CIS reference files
  • Reference files in shared/references/controls/

File Roles

File Purpose By
shared/references/.../{p}.yml Ref metadata 馃
shared/references/.../{p}/*.yml Ref families 馃
products/{p}/controls/nist_800_53.yml Product metadata 馃懁
products/{p}/controls/nist_800_53/*.yml Product families 馃懁

Details

  • Triggered by: Weekly scheduled workflow
  • Date: 2026-09-13 14:17:43 UTC
  • OSCAL: NIST SP 800-53 Revision 5

馃 Generated by weekly sync workflow

This automated update regenerates the CIS鈫扤IST reference file from
the latest OSCAL catalog and CIS benchmark mappings.

Changes: +0/-3 lines in CIS reference files

鈿狅笍  MANUAL ACTION REQUIRED:
Review the diff and manually update the product control files.

Generated by: Weekly NIST 800-53 Sync Workflow
Co-Authored-By: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor Author

Detailed Changes in CIS Reference Files

Changed Family Files

None
馃搧 Family files diff

Tip: Family files (ac.yml, au.yml, cm.yml, etc.) make it
easier to review changes by control area.

@openshift-ci

openshift-ci Bot commented Sep 13, 2026

Copy link
Copy Markdown

Hi @github-actions[bot]. Thanks for your PR.

I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci openshift-ci Bot added the needs-ok-to-test Used by openshift-ci bot. label Sep 13, 2026
@macko1 macko1 added ok-to-test Used by openshift-ci bot. and removed needs-ok-to-test Used by openshift-ci bot. labels Sep 15, 2026
@macko1

macko1 commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

/ok-to-test

@red-hat-konflux-kflux-prd-rh02

Copy link
Copy Markdown
Contributor

All PipelineRuns for this commit have already succeeded. Use /retest <pipeline-name> to re-run a specific pipeline or /test to re-run all pipelines.

@macko1

macko1 commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

/retest

@red-hat-konflux-kflux-prd-rh02

Copy link
Copy Markdown
Contributor

All PipelineRuns for this commit have already succeeded. Use /retest <pipeline-name> to re-run a specific pipeline or /test to re-run all pipelines.

@macko1

macko1 commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

/test

@openshift-ci

openshift-ci Bot commented Sep 15, 2026

Copy link
Copy Markdown

@macko1: The /test command needs one or more targets.
The following commands are available to trigger required jobs:

/test 4.12-e2e-aws-ocp4-cis
/test 4.12-e2e-aws-ocp4-cis-node
/test 4.12-e2e-aws-ocp4-e8
/test 4.12-e2e-aws-ocp4-high
/test 4.12-e2e-aws-ocp4-high-node
/test 4.12-e2e-aws-ocp4-moderate
/test 4.12-e2e-aws-ocp4-moderate-node
/test 4.12-e2e-aws-ocp4-pci-dss
/test 4.12-e2e-aws-ocp4-pci-dss-4-0
/test 4.12-e2e-aws-ocp4-pci-dss-node
/test 4.12-e2e-aws-ocp4-pci-dss-node-4-0
/test 4.12-e2e-aws-ocp4-stig
/test 4.12-e2e-aws-ocp4-stig-node
/test 4.12-e2e-aws-rhcos4-e8
/test 4.12-e2e-aws-rhcos4-high
/test 4.12-e2e-aws-rhcos4-moderate
/test 4.12-e2e-aws-rhcos4-stig
/test 4.12-images
/test 4.14-e2e-aws-ocp4-bsi
/test 4.14-e2e-aws-ocp4-bsi-node
/test 4.14-e2e-aws-ocp4-pci-dss-4-0
/test 4.14-e2e-aws-ocp4-pci-dss-node-4-0
/test 4.14-e2e-aws-rhcos4-bsi
/test 4.14-images
/test 4.16-e2e-aws-ocp4-bsi
/test 4.16-e2e-aws-ocp4-bsi-node
/test 4.16-e2e-aws-ocp4-cis
/test 4.16-e2e-aws-ocp4-cis-node
/test 4.16-e2e-aws-ocp4-e8
/test 4.16-e2e-aws-ocp4-high
/test 4.16-e2e-aws-ocp4-high-node
/test 4.16-e2e-aws-ocp4-moderate
/test 4.16-e2e-aws-ocp4-moderate-node
/test 4.16-e2e-aws-ocp4-pci-dss
/test 4.16-e2e-aws-ocp4-pci-dss-4-0
/test 4.16-e2e-aws-ocp4-pci-dss-node
/test 4.16-e2e-aws-ocp4-pci-dss-node-4-0
/test 4.16-e2e-aws-ocp4-stig
/test 4.16-e2e-aws-ocp4-stig-node
/test 4.16-e2e-aws-rhcos4-bsi
/test 4.16-e2e-aws-rhcos4-e8
/test 4.16-e2e-aws-rhcos4-high
/test 4.16-e2e-aws-rhcos4-moderate
/test 4.16-e2e-aws-rhcos4-stig
/test 4.16-images
/test 4.17-e2e-aws-ocp4-bsi
/test 4.17-e2e-aws-ocp4-bsi-node
/test 4.17-e2e-aws-ocp4-cis
/test 4.17-e2e-aws-ocp4-cis-node
/test 4.17-e2e-aws-ocp4-e8
/test 4.17-e2e-aws-ocp4-high
/test 4.17-e2e-aws-ocp4-high-node
/test 4.17-e2e-aws-ocp4-moderate
/test 4.17-e2e-aws-ocp4-moderate-node
/test 4.17-e2e-aws-ocp4-pci-dss
/test 4.17-e2e-aws-ocp4-pci-dss-4-0
/test 4.17-e2e-aws-ocp4-pci-dss-node
/test 4.17-e2e-aws-ocp4-pci-dss-node-4-0
/test 4.17-e2e-aws-ocp4-stig
/test 4.17-e2e-aws-ocp4-stig-node
/test 4.17-e2e-aws-rhcos4-bsi
/test 4.17-e2e-aws-rhcos4-e8
/test 4.17-e2e-aws-rhcos4-high
/test 4.17-e2e-aws-rhcos4-moderate
/test 4.17-e2e-aws-rhcos4-stig
/test 4.17-images
/test 4.18-e2e-aws-ocp4-bsi
/test 4.18-e2e-aws-ocp4-bsi-node
/test 4.18-e2e-aws-ocp4-cis
/test 4.18-e2e-aws-ocp4-cis-node
/test 4.18-e2e-aws-ocp4-e8
/test 4.18-e2e-aws-ocp4-high
/test 4.18-e2e-aws-ocp4-high-node
/test 4.18-e2e-aws-ocp4-moderate
/test 4.18-e2e-aws-ocp4-moderate-node
/test 4.18-e2e-aws-ocp4-pci-dss
/test 4.18-e2e-aws-ocp4-pci-dss-4-0
/test 4.18-e2e-aws-ocp4-pci-dss-node
/test 4.18-e2e-aws-ocp4-pci-dss-node-4-0
/test 4.18-e2e-aws-ocp4-stig
/test 4.18-e2e-aws-ocp4-stig-node
/test 4.18-e2e-aws-rhcos4-bsi
/test 4.18-e2e-aws-rhcos4-e8
/test 4.18-e2e-aws-rhcos4-high
/test 4.18-e2e-aws-rhcos4-moderate
/test 4.18-e2e-aws-rhcos4-stig
/test 4.18-images
/test 4.19-e2e-aws-ocp4-bsi
/test 4.19-e2e-aws-ocp4-bsi-node
/test 4.19-e2e-aws-ocp4-cis
/test 4.19-e2e-aws-ocp4-cis-node
/test 4.19-e2e-aws-ocp4-e8
/test 4.19-e2e-aws-ocp4-high
/test 4.19-e2e-aws-ocp4-high-node
/test 4.19-e2e-aws-ocp4-moderate
/test 4.19-e2e-aws-ocp4-moderate-node
/test 4.19-e2e-aws-ocp4-pci-dss
/test 4.19-e2e-aws-ocp4-pci-dss-4-0
/test 4.19-e2e-aws-ocp4-pci-dss-node
/test 4.19-e2e-aws-ocp4-pci-dss-node-4-0
/test 4.19-e2e-aws-ocp4-stig
/test 4.19-e2e-aws-ocp4-stig-node
/test 4.19-e2e-aws-rhcos4-bsi
/test 4.19-e2e-aws-rhcos4-e8
/test 4.19-e2e-aws-rhcos4-high
/test 4.19-e2e-aws-rhcos4-moderate
/test 4.19-e2e-aws-rhcos4-stig
/test 4.19-e2e-rosa-ocp4-cis-node
/test 4.19-e2e-rosa-ocp4-pci-dss-node
/test 4.19-images
/test 4.20-e2e-aws-ocp4-bsi
/test 4.20-e2e-aws-ocp4-bsi-node
/test 4.20-e2e-aws-ocp4-cis
/test 4.20-e2e-aws-ocp4-cis-node
/test 4.20-e2e-aws-ocp4-e8
/test 4.20-e2e-aws-ocp4-high
/test 4.20-e2e-aws-ocp4-high-node
/test 4.20-e2e-aws-ocp4-moderate
/test 4.20-e2e-aws-ocp4-moderate-node
/test 4.20-e2e-aws-ocp4-pci-dss
/test 4.20-e2e-aws-ocp4-pci-dss-4-0
/test 4.20-e2e-aws-ocp4-pci-dss-node
/test 4.20-e2e-aws-ocp4-pci-dss-node-4-0
/test 4.20-e2e-aws-ocp4-stig
/test 4.20-e2e-aws-ocp4-stig-node
/test 4.20-e2e-aws-rhcos4-bsi
/test 4.20-e2e-aws-rhcos4-e8
/test 4.20-e2e-aws-rhcos4-high
/test 4.20-e2e-aws-rhcos4-moderate
/test 4.20-e2e-aws-rhcos4-stig
/test 4.20-e2e-rosa-ocp4-cis-node
/test 4.20-e2e-rosa-ocp4-pci-dss-node
/test 4.20-images
/test 4.21-e2e-aws-ocp4-bsi
/test 4.21-e2e-aws-ocp4-bsi-node
/test 4.21-e2e-aws-ocp4-cis
/test 4.21-e2e-aws-ocp4-cis-node
/test 4.21-e2e-aws-ocp4-e8
/test 4.21-e2e-aws-ocp4-high
/test 4.21-e2e-aws-ocp4-high-node
/test 4.21-e2e-aws-ocp4-moderate
/test 4.21-e2e-aws-ocp4-moderate-node
/test 4.21-e2e-aws-ocp4-pci-dss
/test 4.21-e2e-aws-ocp4-pci-dss-4-0
/test 4.21-e2e-aws-ocp4-pci-dss-node
/test 4.21-e2e-aws-ocp4-pci-dss-node-4-0
/test 4.21-e2e-aws-ocp4-stig
/test 4.21-e2e-aws-ocp4-stig-node
/test 4.21-e2e-aws-rhcos4-bsi
/test 4.21-e2e-aws-rhcos4-e8
/test 4.21-e2e-aws-rhcos4-high
/test 4.21-e2e-aws-rhcos4-moderate
/test 4.21-e2e-aws-rhcos4-stig
/test 4.21-e2e-rosa-ocp4-cis-node
/test 4.21-e2e-rosa-ocp4-pci-dss-node
/test 4.21-images
/test 4.22-e2e-aws-ocp4-bsi
/test 4.22-e2e-aws-ocp4-bsi-node
/test 4.22-e2e-aws-ocp4-bsi-node-rhcos10
/test 4.22-e2e-aws-ocp4-cis
/test 4.22-e2e-aws-ocp4-cis-node
/test 4.22-e2e-aws-ocp4-cis-node-rhcos10
/test 4.22-e2e-aws-ocp4-e8
/test 4.22-e2e-aws-ocp4-high
/test 4.22-e2e-aws-ocp4-high-node
/test 4.22-e2e-aws-ocp4-high-node-rhcos10
/test 4.22-e2e-aws-ocp4-moderate
/test 4.22-e2e-aws-ocp4-moderate-node
/test 4.22-e2e-aws-ocp4-moderate-node-rhcos10
/test 4.22-e2e-aws-ocp4-nerc-cip-node-rhcos10
/test 4.22-e2e-aws-ocp4-pci-dss
/test 4.22-e2e-aws-ocp4-pci-dss-4-0
/test 4.22-e2e-aws-ocp4-pci-dss-node
/test 4.22-e2e-aws-ocp4-pci-dss-node-4-0
/test 4.22-e2e-aws-ocp4-pci-dss-node-rhcos10
/test 4.22-e2e-aws-ocp4-stig
/test 4.22-e2e-aws-ocp4-stig-node
/test 4.22-e2e-aws-ocp4-stig-node-rhcos10
/test 4.22-e2e-aws-openshift-node-compliance-rhcos10
/test 4.22-e2e-aws-openshift-platform-compliance-rhcos10
/test 4.22-e2e-aws-rhcos4-bsi
/test 4.22-e2e-aws-rhcos4-bsi-rhcos10
/test 4.22-e2e-aws-rhcos4-e8
/test 4.22-e2e-aws-rhcos4-e8-rhcos10
/test 4.22-e2e-aws-rhcos4-high
/test 4.22-e2e-aws-rhcos4-high-rhcos10
/test 4.22-e2e-aws-rhcos4-moderate
/test 4.22-e2e-aws-rhcos4-moderate-rhcos10
/test 4.22-e2e-aws-rhcos4-nerc-cip-rhcos10
/test 4.22-e2e-aws-rhcos4-stig
/test 4.22-e2e-aws-rhcos4-stig-rhcos10
/test 4.22-e2e-rosa-ocp4-cis-node
/test 4.22-e2e-rosa-ocp4-pci-dss-node
/test 4.22-images
/test 5.0-images
/test e2e-aws-ocp4-bsi
/test e2e-aws-ocp4-bsi-node
/test e2e-aws-ocp4-cis
/test e2e-aws-ocp4-cis-arm
/test e2e-aws-ocp4-cis-node
/test e2e-aws-ocp4-cis-node-arm
/test e2e-aws-ocp4-e8
/test e2e-aws-ocp4-high
/test e2e-aws-ocp4-high-node
/test e2e-aws-ocp4-moderate
/test e2e-aws-ocp4-moderate-arm
/test e2e-aws-ocp4-moderate-node
/test e2e-aws-ocp4-moderate-node-arm
/test e2e-aws-ocp4-pci-dss
/test e2e-aws-ocp4-pci-dss-4-0
/test e2e-aws-ocp4-pci-dss-node
/test e2e-aws-ocp4-pci-dss-node-4-0
/test e2e-aws-ocp4-stig
/test e2e-aws-ocp4-stig-node
/test e2e-aws-openshift-node-compliance-rhcos10
/test e2e-aws-openshift-platform-compliance
/test e2e-aws-openshift-platform-compliance-rhcos10
/test e2e-aws-rhcos4-bsi
/test e2e-aws-rhcos4-e8
/test e2e-aws-rhcos4-high
/test e2e-aws-rhcos4-moderate
/test e2e-aws-rhcos4-moderate-arm
/test e2e-aws-rhcos4-stig
/test images

The following commands are available to trigger optional jobs:

/test e2e-aws-openshift-node-compliance

Use /test all to run the following jobs that were automatically triggered:

pull-ci-ComplianceAsCode-content-master-4.12-images
pull-ci-ComplianceAsCode-content-master-4.14-images
pull-ci-ComplianceAsCode-content-master-4.16-images
pull-ci-ComplianceAsCode-content-master-4.17-images
pull-ci-ComplianceAsCode-content-master-4.18-images
pull-ci-ComplianceAsCode-content-master-4.19-images
pull-ci-ComplianceAsCode-content-master-4.20-images
pull-ci-ComplianceAsCode-content-master-4.21-images
pull-ci-ComplianceAsCode-content-master-4.22-images
pull-ci-ComplianceAsCode-content-master-5.0-images
pull-ci-ComplianceAsCode-content-master-e2e-aws-openshift-platform-compliance
pull-ci-ComplianceAsCode-content-master-images
Details

In response to this:

/test

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci

openshift-ci Bot commented Sep 15, 2026

Copy link
Copy Markdown

@github-actions[bot]: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-openshift-platform-compliance a830598 link true /test e2e-aws-openshift-platform-compliance
ci/prow/4.12-images a830598 link true /test 4.12-images

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@macko1 macko1 self-assigned this Sep 18, 2026
@github-actions

Copy link
Copy Markdown
Contributor Author

馃攧 Workflow Re-run Update

The CIS-NIST sync workflow ran again at 2026-09-20 14:17:32 UTC.
The reference files are still up to date with the same changes as this PR.

Automated comment from workflow run 35515937614

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ok-to-test Used by openshift-ci bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant