ISO/IEC 27001
ISO/IEC 27001:2022. Run with --compliance=Iso27001 to keep only the findings mapped to it, with their control ids in a ControlId column.
Controls covered: Access, backup, crypto, logging, monitoring, vulnerability, network security
Official text: ISO/IEC 27001:2022.
| Gravity | ControlId | Code | Id | Description | Context | SubContext |
|---|---|---|---|---|---|---|
| Critical | A.5.17, A.8.5 | CC0004 | access/users/root@pam | root@pam has no TFA configured — full access protected only by password | Cluster | Access |
| Critical | A.5.15, A.8.2 | CG0006 | nodes/pve02/lxc/101 | Privileged container has AppArmor disabled — no kernel confinement, root inside has unrestricted host access | Lxc | Security |
| Critical | A.8.13 | CG0002 | nodes/pve02/qemu/203 | Disk 'scsi0' disabled for backup | Qemu | Backup |
| Warning | A.8.8 | WN0013 | nodes/pve01 | Node requires reboot: running kernel '6.8.12-20-pve' but newer kernel '6.8.12-43-pve' is installed | Node | Reboot |
| Warning | A.5.30, A.8.16 | WS0009 | nodes/pve01/storage/pbs01 | Storage usage 80% - 2.58 TB of 3.22 TB | Storage | Usage |
| Warning | A.8.8 | WG0037 | nodes/pve01/qemu/1010 | CPU type 'kvm64' is missing security flags: +spec-ctrl, +ssbd, +pcid, +md-clear — add to cpu flags to mitigate Spectre/Meltdown/MDS | Qemu | CPU |
| Warning | A.8.13 | WG0017 | nodes/pve02/qemu/999 | vzdump backup not configured | Qemu | Backup |
| Warning | A.8.8 | WG0002 | nodes/pve01/qemu/1013 | OS 'Microsoft Windows 8.x/2012/2012r2' not maintained from vendor! | Qemu | OSNotMaintained |
| Info | A.5.30 | IC0002 | cluster | No HA resources configured — VMs will not automatically restart on node failure | Cluster | HA |
| Ok | A.8.13 | WC0001 | cluster/backup | 3 backup job(s) configured at cluster level | Cluster | Backup |
| Ok | A.8.20, A.8.22 | WC0003 | cluster | Cluster firewall is enabled | Cluster | Firewall |
| Ok | A.8.13 | WG0017 | nodes/pve01/qemu/100 | Guest is covered by at least one enabled backup job | Qemu | Backup |
| Ok | A.8.13 | WG0017 | nodes/pve01/qemu/101 | Guest is covered by at least one enabled backup job | Qemu | Backup |
One row per object: a check failing — or passing — on ten VMs gives ten rows, all the controls of a finding in the same row.
Ok rows come from --full, or IncludeOkResult: true in the settings file.Controls
Section titled “Controls”In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.
| Control | Title | Where it appears |
|---|---|---|
| A.5.15 | Access control | Privileged ACL, container isolation, asset/pool management |
| A.5.16 | Identity management | User lifecycle, notification email |
| A.5.17 | Authentication information | TFA on admin / root / external realms |
| A.5.18 | Access rights | Lifecycle (expiration, disabled users, groups, roles) |
| A.5.30 | ICT readiness for business continuity | HA, replication, single-node cluster, NIC bond, storage availability |
| A.8.2 | Privileged access rights | Admin ACL on root, privileged containers, token privilege separation |
| A.8.5 | Secure authentication | TFA |
| A.8.8 | Management of technical vulnerabilities | Patch level, OS EOL, kernel/version mismatch, CPU security flags, CVE |
| A.8.13 | Information backup | Backup config, retention, schedule, recent backups, disk inclusion, storage |
| A.8.15 | Logging | Cluster log errors, firewall rule logging, task failure rate, NTP, metric server |
| A.8.16 | Monitoring activities | Task history, services, NTP, storage availability, metric server, user notification |
| A.8.20 | Networks security | Cluster firewall, node firewall, policy, 0.0.0.0/0 rules, duplicate MAC |
| A.8.22 | Segregation of networks | VM/CT firewall, duplicate MAC |
| A.8.24 | Use of cryptography | Certificates (expired, expiring, self-signed) |
How the mapping works, and its limits: Compliance overview.