Skip to content

Commit 6fc1363

Browse files
authored
Merge pull request #74381 from rhmdnd/clarify-what-compliance-means
2 parents bbced86 + 68fa1cf commit 6fc1363

File tree

2 files changed

+27
-9
lines changed

2 files changed

+27
-9
lines changed

security/compliance_operator/co-overview.adoc

Lines changed: 16 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,12 +4,21 @@
44
include::_attributes/common-attributes.adoc[]
55
:context: co-overview
66

7-
{product-title} Compliance Operator (CO) runs compliance scans and provides remediations to assist users in meeting compliance standards. For the latest updates, see the xref:../../security/compliance_operator/compliance-operator-release-notes.adoc#compliance-operator-release-notes[Compliance Operator release notes]. If needed, you can engage link:https://access.redhat.com/support/[Red Hat support].
8-
9-
[IMPORTANT]
10-
====
11-
The Compliance Operator does not automatically perform remediations. Ensuring compliance standards are met is required by the user.
12-
====
7+
The {product-title} Compliance Operator assists users by automating the
8+
inspection of numerous technical implementations and compares those against
9+
certain aspects of industry standards, benchmarks, and baselines; the
10+
Compliance Operator is not an auditor. In order to be compliant or certified
11+
under these various standards, you need to engage an authorized auditor such as
12+
a Qualified Security Assessor (QSA), Joint Authorization Board (JAB), or other
13+
industry recognized regulatory authority to assess your environment.
14+
15+
The Compliance Operator makes recommendations based on generally available
16+
information and practices regarding such standards and may assist with
17+
remediations, but actual compliance is your responsibility. You are required to
18+
work with an authorized auditor to achieve compliance with a standard. For the
19+
latest updates, see the
20+
xref:../../security/compliance_operator/compliance-operator-release-notes.adoc#compliance-operator-release-notes[Compliance
21+
Operator release notes]
1322

1423
[discrete]
1524
==== Compliance Operator concepts
@@ -47,4 +56,4 @@ xref:../../security/compliance_operator/co-scans/compliance-operator-advanced.ad
4756

4857
xref:../../security/compliance_operator/co-scans/compliance-operator-troubleshooting.adoc#compliance-operator-troubleshooting[Troubleshooting the Compliance Operator]
4958

50-
xref:../../security/compliance_operator/co-scans/oc-compliance-plug-in-using.adoc#using-oc-compliance-plug-in[Using the oc-compliance plugin]
59+
xref:../../security/compliance_operator/co-scans/oc-compliance-plug-in-using.adoc#using-oc-compliance-plug-in[Using the oc-compliance plugin]

security/compliance_operator/co-scans/compliance-operator-supported-profiles.adoc

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,16 @@
44
include::_attributes/common-attributes.adoc[]
55
:context: compliance-operator-supported-profiles
66

7-
There are several profiles available as part of the Compliance Operator (CO) installation. While you can use the following profiles to assess gaps in a cluster, usage alone does not infer or guarantee compliance with a particular profile.
7+
There are several profiles available as part of the Compliance Operator (CO)
8+
installation. While you can use the following profiles to assess gaps in a
9+
cluster, usage alone does not infer or guarantee compliance with a particular
10+
profile and is not an auditor.
11+
12+
In order to be compliant or certified under these various standards, you need
13+
to engage an authorized auditor such as a Qualified Security Assessor (QSA),
14+
Joint Authorization Board (JAB), or other industry recognized regulatory
15+
authority to assess your environment. You are required to work with an
16+
authorized auditor to achieve compliance with a standard.
817

918

1019
[IMPORTANT]
@@ -18,4 +27,4 @@ include::modules/compliance-supported-profiles.adoc[leveloffset=+1]
1827
[role="_additional-resources"]
1928
== Additional resources
2029

21-
* xref:../../../security/compliance_operator/co-concepts/compliance-operator-understanding.html#compliance_profile_types_understanding-compliance[Compliance Operator profile types]
30+
* xref:../../../security/compliance_operator/co-concepts/compliance-operator-understanding.adoc#compliance_profile_types_understanding-compliance[Compliance Operator profile types]

0 commit comments

Comments
 (0)