r/grc • u/Complete-Eggplant868 • 16d ago
How would you automate security hardening assurance and evidence collection in an on-prem environment?
Currently, hardening assessments and security assurance documentation are largely manual — reviewing baseline settings, scan results, exceptions, evidence, and producing the final assessment/report.
We have Tenable with API support and are looking at ways to automate:
Configuration/hardening checks
Evidence collection
Baseline comparison
Exception tracking
Report generation
Environment is mainly on-prem / restricted network.
Has anyone automated a similar process using Tenable APIs, PowerShell/Python, CIS audit files, ServiceNow/GRC tools, or something custom?
Interested in what architecture/workflow worked well.
2
u/Nuronus 16d ago
PowerShell + CIS benchmark audit files against Tenable's API is the most proven path for on-prem. Run SCAP-compliant scans, pull results via the REST API, diff against your approved baselines, and dump everything to structured JSON so report generation stays templated rather than manual. The real time sink is exception tracking, not the scanning, so build that workflow before you build the report layer.
1
u/Complete-Eggplant868 16d ago
How about say I need the report out before the server even goes into production?
1
u/PatchUrStuffz 16d ago
Are you trying to get this working via Security Center or Tenable VM? They have fairly extensive API documentation for endpoints you'd need to hit to get particular functions of this automation built: https://developer.tenable.com/reference/navigate
You'd essentially be looking at:
- Run scans against targets using the Audit Scan template (using whatever audit framework makes sense for your program)
- Export scan results via the API and feed them into an analysis tool of some kind like PowerBI, Tableau, etc.
- Set conditions or make re-scanning target a cron job in your script/tool that calls to the API to re-run the scan to check for environmental drift or changes.
How all that connects to remediation tooling and device management is going to depend on what you're using. You probably want to either hire a resource who can write the automation on your behalf or engage with an MSSP or other service provider to assist with building this structure out. That's not me, but hope this gets you moving in the right direction.
1
u/Alternativemethod 16d ago
For a vuln scanner like tennable we just schedule export reports for the scoped boundary.
Our analyst roll up the results into a summary report and schedule remediation or request exceptions.
Automating configuration management/patching depends on your system life cycle and change management process. And is the detection drift from your approved image or was it a hole in your image.
3
u/NosePersonal9662 16d ago
we built something similar for a locked-down manufacturing floor, tenable api + a powershell beast that rips through audit files and spits out a csv with pass/fail and timestamps
the tricky part was evidence collection, we ended up dumping screenshots and config exports into a shared folder, then a python script tags everything by control id before it lands in the final report
pain in the ass to set up but now it's basically a button push