As we discussed earlier in this chapter, the oscap tool is a command-line utility designed for scanning the local machine that it is installed on. The security policies that you wish to audit the host against must also be on the filesystem of the host that it runs on. If you have completed the steps in the section entitled Evaluating and selecting policies, then you should already have everything you need.
With that said, if using the oscap tool to scan your infrastructure is going to be your way forward, you may wish to consider Ansible as a tool to both install it and gather the results when the scan is complete.
Before we come to this, let's look at how we might scan a single host:
- Assuming ...