Skip to content

BSI C5

C5 — Cloud Computing Compliance Criteria Catalogue (BSI Germany, C5:2020). Run with --compliance=C5 to keep only the findings mapped to it, with their control ids in a ControlId column.

Controls covered: IDM-01/02/03/06/09, CRY-01/02, COS-01, OPS-06/10/13/18/23, BCM-03/04

Official text: C5 criteria catalogue.

In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.

Subset of C5:2020 criteria that are technically verifiable on a Proxmox VE cluster. Identifiers and titles as in the English edition (CRY and COS are KRY and KOS in the German one).

Control Title Where it appears
IDM-01 Policy for user accounts and access rights (declared)
IDM-02 Granting and change of user accounts and access rights (declared)
IDM-03 Locking and withdrawal of user accounts Account lifecycle: expiration, unused groups and roles, tokens of disabled users, token comments
IDM-06 Privileged access rights ACL, container privileged, root@pam token privsep
IDM-09 Authentication mechanisms TFA (root@pam, admins, group, realm)
CRY-01 Policy for the use of encryption procedures and key management (declared)
CRY-02 Encryption of data for transmission (transport encryption) Certificates (expired / expiring), TLS
COS-01 Technical safeguards Cluster/node firewall, guest firewall, malware-defence baseline, duplicate MAC
OPS-06 Data Backup and Recovery – Concept All backup checks, backup storage availability, disk cache integrity
OPS-10 Logging and Monitoring – Concept Cluster log, task history, firewall audit logging, services, NTP, user notifications, metric server
OPS-13 Logging and Monitoring – Identification of Events Cluster log, task history, firewall audit logging, services
OPS-18 Managing Vulnerabilities, Malfunctions and Errors – Concept Patch, PVE EOL, CVE, important updates, outdated machine type
OPS-23 Managing Vulnerabilities, Malfunctions and Errors – System Hardening Container isolation, patch consistency across nodes
BCM-03 Planning business continuity HA, replication, single-node, HA guest checks
BCM-04 Verification, updating and testing of the business continuity (declared)

How the mapping works, and its limits: Compliance overview.