- 安裝openscap
$ sudo yum install -y openscap-scanner scap-security-guide
- 確認PCI-DSS profile已經安裝好
$ oscap info /usr/share/xml/scap/ssg/content/ssg-centos7-ds.xml
- 評估PCI-DSS相關的內容
$ oscap xccdf eval --results results.xml --profile xccdf_org.ssgproject.content_profile_pci-dss /usr/share/xml/scap/ssg/content/ssg-centos7-ds.xml
- 產生方便閱讀的html格式報告
$ oscap xccdf generate report --output report.html results.xml