Chapter 2. Using the Compliance Operator with RHACS
You can configure RHACS to use the Compliance Operator for compliance reporting and remediation with OpenShift Container Platform clusters. RHACS reports results from the Compliance Operator in the RHACS Compliance Coverage page.
You must install the Compliance Operator on the cluster that you want reviewed for compliance.
The Compliance Operator automates the review of numerous technical implementations and compares them with certain aspects of industry standards, benchmarks, and baselines.
The Compliance Operator is not an auditor. To comply or certify to these various standards, you must engage an authorized auditor such as a Qualified Security Assessor (QSA), Joint Authorization Board (JAB), or other industry-recognized regulatory authority to assess your environment.
+ The Compliance Operator makes recommendations based on generally available information and practices that relate to such standards and can assist with remediation, but actual compliance is your responsibility. You are required to work with an authorized auditor to achieve compliance with a standard.
For the latest updates, see the Compliance Operator release notes.
2.1. Installing the Compliance Operator Copy linkLink copied to clipboard!
Install the Compliance Operator by using the Software Catalog.
Procedure
-
In the web console, go to the Ecosystem
Software Catalog page. - Enter compliance operator into the Filter by keyword box to find the Compliance Operator.
- Select the Compliance Operator to view the details page.
- Read the information about the Operator, and then click Install.
- Optional: If you use the compliance feature, you can schedule your scan by using RHACS to create a compliance scan schedule. For more information about scheduling a compliance scan by using the compliance feature, see "Customizing and automating your compliance scans".