Rule Definitions and Standards
View and manage the standards and associated rules supported by Harness SCS
The Rule Definitions section offers a complete list of all the standards and associated rules supported by Harness SCS. These rules are applied to various target types, and the overall compliance posture is presented in the Compliance section of SCS. Go to Compliance Summary to understand how to manage the compliance status.

The page offers details about the rule, including its description, severity (defined by Harness), the standard with the rule ID to which it belongs, and the target type to which it applies (e.g., code repository, artifact, CI/CD).
You can apply filters specific to standards to view the rules associated with those standards and use the search function to find specific rules.
Supported standards and rules
Harness supports the following standards:
CIS benchmarks
The following CIS v1.0 rules are supported by Harness for the evaluations, and Harness will continue to add more rules across different target types. For more detailed information, refer to the official CIS documentation
OWASP Top 10 CI/CD security risks
The following rules are supported by Harness to perform evaluations, and Harness will continue to add more rules across different target types. For more detailed information, refer to the official OWASP documentation.
OSS Top 10 Risks
The OWASP Top 10 Open Source Software (OSS) Risks provide a clear framework for understanding critical security threats in open source dependencies, including outdated components, unmaintained projects, supply chain attacks, and malicious packages. For more detailed information, refer to the official OWASP documentation.
Last updated
Was this helpful?