About Pavois

Pavois audits the configuration your services actually run (sshd -T, sysctl, systemctl, auditctl), not just the files on disk. It maps each control to every applicable standard (CIS, ANSSI BP-028, NIST, PCI-DSS, STIG), grades the result A to E, and hardens it as code with a state-aware Chef plan. A PASS carries a qualified verdict: running now versus reboot-survivable.

The author

Pavois is designed and maintained by Stéphane Robert, a DevOps engineer who writes about hardening, cloud and automation on his blog. The project extends that work: making effective Linux compliance opposable and reproducible.

To go further, his hardening guides are onblog.stephane-robert.info.

The project

Pavois is 100% CINC/InSpec, agentless, CI-friendly. Control definitions derive from ComplianceAsCode/SSG (BSD-3) and are cross-validated against ansible-lockdown. See theAttribution & licensing page.