BSI IT-Grundschutz
BSI IT-Grundschutz — Kompendium Edition 2023 (Germany). Run with --compliance=BsiGrundschutz to keep only the findings mapped to it, with their control ids in a ControlId column.
Controls covered: CON.1.A1, CON.3.A5, OPS.1.1.3.A15, OPS.1.1.5.A3/A4, ORP.4.A10/A21, SYS.1.1.A19, SYS.1.5.A4/A17/A20, SYS.1.6.A17, SYS.1.8.A13
Official text: IT-Grundschutz-Kompendium.
Controls
Section titled “Controls”In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.
Requirements (Anforderungen) of the IT-Grundschutz-Kompendium, Edition 2023 — the last edition; it is superseded by Grundschutz++ (published October 2026, certifiable from 2027) and remains certifiable until November 2031. Titles are the German ones of the Kompendium; the letter is the protection level: (B) Basis, (S) Standard, (H) elevated protection needs.
| Requirement | Title | Where it appears |
|---|---|---|
| CON.1.A1 | Auswahl geeigneter kryptografischer Verfahren (B) | Certificates, TLS |
| CON.3.A5 | Regelmäßige Datensicherung (B) | All backup checks |
| OPS.1.1.3.A15 | Regelmäßige Aktualisierung von IT-Systemen und Software (B) | Patch, PVE and OS end of life, CVE, important updates |
| OPS.1.1.5.A3 | Konfiguration der Protokollierung auf System- und Netzebene (B) | Cluster log, task history, firewall audit logging |
| OPS.1.1.5.A4 | Zeitsynchronisation der IT-Systeme (B) | Node time offset (WN0014) |
| ORP.4.A10 | Schutz von Benutzendenkennungen mit weitreichenden Berechtigungen (S) | ACL, root@pam token privsep |
| ORP.4.A21 | Mehr-Faktor-Authentisierung (H) | TFA |
| SYS.1.1.A19 | Einrichtung lokaler Paketfilter (S) | Cluster/node firewall, guest firewall |
| SYS.1.5.A4 | Sichere Konfiguration eines Netzes für virtuelle Infrastrukturen (B) | Guest firewall, duplicate MAC |
| SYS.1.5.A17 | Überwachung des Betriebszustands und der Konfiguration der virtuellen Infrastruktur (S) | Metric server, services, monitoring |
| SYS.1.5.A20 | Verwendung von hochverfügbaren Architekturen (H) | HA, replication, quorum, single-node |
| SYS.1.6.A17 | Ausführung von Containern ohne Privilegien (S) | Privileged containers, container isolation |
| SYS.1.8.A13 | Überwachung und Verwaltung von Speicherlösungen (S) | Storage usage, thin provisioning |
How the mapping works, and its limits: Compliance overview.