cfbs add compliance-report-fwupd@0.2.0
Compliance report definition for firmware security posture via fwupd.
Imports a "Firmware Security (fwupd)" report into Mission Portal that tracks Host Security Identifier (HSI) levels, fwupd installation, and firmware update status across the fleet.
The report contains 49 conditions: 7 rolled-up checks (HSI level thresholds, fwupd installation, update status) and 42 per-attribute checks covering every individual HSI firmware security test.

fwupd_cpu_vendor_intel, fwupd_cpu_vendor_amd,
fwupd_oem_vendor_hp) that the compliance conditions reference| Condition | Category | Severity |
|---|---|---|
| fwupd installed | Firmware tooling | high |
| HSI Level 1+ (Critical) | HSI Level Overview | high |
| HSI Level 2+ (Important) | HSI Level Overview | medium |
| HSI Level 3+ (Recommended) | HSI Level Overview | low |
| HSI Level 4 (Complete) | HSI Level Overview | low |
| No pending firmware updates | Firmware updates | medium |
| Firmware status healthy | Firmware updates | medium |
HSI level checks are cumulative thresholds – a host at HSI:3 passes the Level 1+, 2+, and 3+ conditions but fails Level 4.
Each individual HSI firmware security check is a separate compliance
condition. Every one matches an exact item against the
Firmware HSI failing slist from inventory-fwupd, whose items follow
the pattern L<level>: <Name>.
Per-attribute conditions use condition_for: "failing" – a host is
only marked failing when the check appears in that list. Hosts that
don't report a given check (e.g., Intel-only checks on AMD hardware, or
VMs without HSI data) show as "not evaluated" rather than failing,
because the check appears in neither the failing nor the passing list. The checks are defined by the
fwupd HSI specification.
| Condition | List item | Platform |
|---|---|---|
| UEFI SecureBoot | L1: UEFI secure boot |
All |
| TPM 2.0 Present | L1: TPM v2.0 |
All |
| Empty PCR in TPM | L1: TPM empty PCRs |
All |
| UEFI Platform Key | L1: UEFI platform key |
All |
| BIOS Capsule Updates | L1: BIOS firmware updates |
All |
| Supported CPU | L1: Supported CPU |
All |
| UEFI BootService Variables | L1: UEFI bootservice variables |
All |
| BIOS Write Enable (BWE) | L1: SPI write |
Intel |
| BIOS Lock Enable (BLE) | L1: SPI lock |
Intel |
| SMM BIOS Write Protect | L1: SPI BIOS region |
Intel |
| Read-only SPI Descriptor | L1: SPI descriptor |
Intel |
| Platform Debug (Intel DCI) | L1: Platform debugging |
Intel |
| ME Manufacturing Mode | L1: csme manufacturing mode |
Intel |
| ME Flash Descriptor Override | L1: csme override |
Intel |
| ME BootGuard Platform Key | L1: MEI key manifest |
Intel |
| CSME Version | L1: CSME version |
Intel |
| Part is Fused | L1: Part is fused |
Intel |
| AMD Microcode Signature | L1: AMD microcode signature |
AMD |
| SMM Locked Down | L1: SMM locked down |
AMD |
| Condition | List item | Platform |
|---|---|---|
| DMA Protection (IOMMU) | L2: IOMMU |
All |
| PCR0 TPM Event Log | L2: TPM PCR0 reconstruction |
All |
| BIOS Rollback Protection | L2: BIOS rollback protection |
All |
| Intel BootGuard Enabled | L2: Intel BootGuard |
Intel |
| Intel BootGuard Verified | L2: Intel BootGuard verified boot |
Intel |
| Intel BootGuard ACM | L2: Intel BootGuard ACM protected |
Intel |
| Intel BootGuard OTP | L2: Intel BootGuard OTP fuse |
Intel |
| Part is Debug Locked | L2: Platform debugging |
Intel |
| Intel GDS Mitigation | L2: Intel GDS mitigation |
Intel |
| AMD Platform Secure Boot | L2: AMD platform secure boot |
AMD |
| AMD SPI Write Protections | L2: AMD SPI write protections |
AMD |
| HP SureStart | L2: HP SureStart |
HP |
| Condition | List item | Platform |
|---|---|---|
| Suspend-to-Idle | L3: Suspend-to-idle |
All |
| Suspend to RAM Disabled | L3: Suspend-to-ram |
All |
| Pre-boot DMA Protection | L3: Pre-boot DMA protection |
All |
| CET Available | L3: CET Platform |
All |
| CET Utilized by OS | L3: CET OS Support |
All |
| Early-boot UEFI Memory Protections | L3: UEFI memory protections |
All |
| Intel BootGuard Policy | L3: Intel BootGuard error policy |
Intel |
| AMD SPI Replay Protections | L3: AMD SPI replay protections |
AMD |
| Condition | List item | Platform |
|---|---|---|
| DRAM Memory Encryption | L4: Encrypted RAM |
All |
| SMAP | L4: SMAP |
All |
| AMD Secure Processor Rollback | L4: AMD rollback protection |
AMD |
| Category | Conditions | Scope |
|---|---|---|
| HSI Level Overview | 4 | Rolled-up level thresholds |
| HSI Level 1 - Critical | 19 | Per-attribute checks |
| HSI Level 2 - Important | 12 | Per-attribute checks |
| HSI Level 3 - Recommended | 8 | Per-attribute checks |
| HSI Level 4 - Complete | 3 | Per-attribute checks |
| Firmware updates | 2 | Update status |
| Firmware tooling | 1 | fwupd installation |
Linux only. Platform-specific conditions use host_filter class
expressions so they only activate on relevant hardware:
| Platform | host_filter |
Conditions | Detection |
|---|---|---|---|
| All | linux |
25 | – |
| Intel | fwupd_cpu_vendor_intel |
17 | /proc/cpuinfo vendor_id |
| AMD | fwupd_cpu_vendor_amd |
6 | /proc/cpuinfo vendor_id |
| HP | fwupd_oem_vendor_hp |
1 | /sys/class/dmi/id/sys_vendor |
These classes are defined by the inventory-fwupd module.