ISO/IEC 27017
ISO/IEC 27017:2015 — Cloud-specific extensions. Run with --compliance=Iso27017 to keep only the findings mapped to it, with their control ids in a ControlId column.
Controls covered: CLD.6.3.1, CLD.8.1.5, CLD.9.5.1/2, CLD.12.1.5, CLD.12.4.5, CLD.13.1.4
Official text: ISO/IEC 27017:2015. A 2026 edition has since been published; this mapping follows the 2015 one.
Controls
Section titled “Controls”In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.
Adds the CLD.* controls to ISO 27001. The base ISO 27001 controls are on the ISO 27001 page.
| Control | Title | Where it appears |
|---|---|---|
| CLD.6.3.1 | Shared roles and responsibilities in cloud | HA, replication, single-node, NIC bond |
| CLD.8.1.5 | Removal of cloud service customer assets | (declared) |
| CLD.9.5.1 | Segregation in virtual computing environments | (declared) |
| CLD.9.5.2 | Virtual machine hardening | Patch and version consistency across nodes, PVE and OS end of life, CVE, CPU security flags, outdated machine type |
| CLD.12.1.5 | Administrator’s operational security | (declared) |
| CLD.12.4.5 | Monitoring of cloud services | Cluster log, task failures, NTP, services, metric server |
| CLD.13.1.4 | Alignment of security for virtual and physical networks | Firewall, duplicate MAC |
How the mapping works, and its limits: Compliance overview.