The defaults chosen for this project sometimes fail the scap-security-guide checks. It would be nice to create a tailoring file for variables here that would allow ssg to pass its checks. Notably, the daemon umask settings and the audit failure actions do not pass the ssg default checks. (see ComplianceAsCode/content#2755)