Skip to content

BSI IT-Grundschutz

BSI IT-Grundschutz — Kompendium Edition 2023 (Germany). Run with --compliance=BsiGrundschutz to keep only the findings mapped to it, with their control ids in a ControlId column.

Controls covered: CON.1.A1, CON.3.A5, OPS.1.1.3.A15, OPS.1.1.5.A3/A4, ORP.4.A10/A21, SYS.1.1.A19, SYS.1.5.A4/A17/A20, SYS.1.6.A17, SYS.1.8.A13

Official text: IT-Grundschutz-Kompendium.

In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.

Requirements (Anforderungen) of the IT-Grundschutz-Kompendium, Edition 2023 — the last edition; it is superseded by Grundschutz++ (published October 2026, certifiable from 2027) and remains certifiable until November 2031. Titles are the German ones of the Kompendium; the letter is the protection level: (B) Basis, (S) Standard, (H) elevated protection needs.

Requirement Title Where it appears
CON.1.A1 Auswahl geeigneter kryptografischer Verfahren (B) Certificates, TLS
CON.3.A5 Regelmäßige Datensicherung (B) All backup checks
OPS.1.1.3.A15 Regelmäßige Aktualisierung von IT-Systemen und Software (B) Patch, PVE and OS end of life, CVE, important updates
OPS.1.1.5.A3 Konfiguration der Protokollierung auf System- und Netzebene (B) Cluster log, task history, firewall audit logging
OPS.1.1.5.A4 Zeitsynchronisation der IT-Systeme (B) Node time offset (WN0014)
ORP.4.A10 Schutz von Benutzendenkennungen mit weitreichenden Berechtigungen (S) ACL, root@pam token privsep
ORP.4.A21 Mehr-Faktor-Authentisierung (H) TFA
SYS.1.1.A19 Einrichtung lokaler Paketfilter (S) Cluster/node firewall, guest firewall
SYS.1.5.A4 Sichere Konfiguration eines Netzes für virtuelle Infrastrukturen (B) Guest firewall, duplicate MAC
SYS.1.5.A17 Überwachung des Betriebszustands und der Konfiguration der virtuellen Infrastruktur (S) Metric server, services, monitoring
SYS.1.5.A20 Verwendung von hochverfügbaren Architekturen (H) HA, replication, quorum, single-node
SYS.1.6.A17 Ausführung von Containern ohne Privilegien (S) Privileged containers, container isolation
SYS.1.8.A13 Überwachung und Verwaltung von Speicherlösungen (S) Storage usage, thin provisioning

How the mapping works, and its limits: Compliance overview.