Skip to content

ISO/IEC 27001

ISO/IEC 27001:2022. Run with --compliance=Iso27001 to keep only the findings mapped to it, with their control ids in a ControlId column.

Controls covered: Access, backup, crypto, logging, monitoring, vulnerability, network security

Official text: ISO/IEC 27001:2022.

cv4pve-diag --host=pve01 --api-token='diag@pve!audit=…' --compliance=Iso27001 execute --full
GravityControlIdCodeIdDescriptionContextSubContext
CriticalA.5.17, A.8.5CC0004access/users/root@pamroot@pam has no TFA configured — full access protected only by passwordClusterAccess
CriticalA.5.15, A.8.2CG0006nodes/pve02/lxc/101Privileged container has AppArmor disabled — no kernel confinement, root inside has unrestricted host accessLxcSecurity
CriticalA.8.13CG0002nodes/pve02/qemu/203Disk 'scsi0' disabled for backupQemuBackup
WarningA.8.8WN0013nodes/pve01Node requires reboot: running kernel '6.8.12-20-pve' but newer kernel '6.8.12-43-pve' is installedNodeReboot
WarningA.5.30, A.8.16WS0009nodes/pve01/storage/pbs01Storage usage 80% - 2.58 TB of 3.22 TBStorageUsage
WarningA.8.8WG0037nodes/pve01/qemu/1010CPU type 'kvm64' is missing security flags: +spec-ctrl, +ssbd, +pcid, +md-clear — add to cpu flags to mitigate Spectre/Meltdown/MDSQemuCPU
WarningA.8.13WG0017nodes/pve02/qemu/999vzdump backup not configuredQemuBackup
WarningA.8.8WG0002nodes/pve01/qemu/1013OS 'Microsoft Windows 8.x/2012/2012r2' not maintained from vendor!QemuOSNotMaintained
InfoA.5.30IC0002clusterNo HA resources configured — VMs will not automatically restart on node failureClusterHA
OkA.8.13WC0001cluster/backup3 backup job(s) configured at cluster levelClusterBackup
OkA.8.20, A.8.22WC0003clusterCluster firewall is enabledClusterFirewall
OkA.8.13WG0017nodes/pve01/qemu/100Guest is covered by at least one enabled backup jobQemuBackup
OkA.8.13WG0017nodes/pve01/qemu/101Guest is covered by at least one enabled backup jobQemuBackup
One row per object: a check failing — or passing — on ten VMs gives ten rows, all the controls of a finding in the same row. Ok rows come from --full, or IncludeOkResult: true in the settings file.

In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.

Control Title Where it appears
A.5.15 Access control Privileged ACL, container isolation, asset/pool management
A.5.16 Identity management User lifecycle, notification email
A.5.17 Authentication information TFA on admin / root / external realms
A.5.18 Access rights Lifecycle (expiration, disabled users, groups, roles)
A.5.30 ICT readiness for business continuity HA, replication, single-node cluster, NIC bond, storage availability
A.8.2 Privileged access rights Admin ACL on root, privileged containers, token privilege separation
A.8.5 Secure authentication TFA
A.8.8 Management of technical vulnerabilities Patch level, OS EOL, kernel/version mismatch, CPU security flags, CVE
A.8.13 Information backup Backup config, retention, schedule, recent backups, disk inclusion, storage
A.8.15 Logging Cluster log errors, firewall rule logging, task failure rate, NTP, metric server
A.8.16 Monitoring activities Task history, services, NTP, storage availability, metric server, user notification
A.8.20 Networks security Cluster firewall, node firewall, policy, 0.0.0.0/0 rules, duplicate MAC
A.8.22 Segregation of networks VM/CT firewall, duplicate MAC
A.8.24 Use of cryptography Certificates (expired, expiring, self-signed)

How the mapping works, and its limits: Compliance overview.