Skip to content

NIS2

NIS2 — Art. 21. Run with --compliance=Nis2 to keep only the findings mapped to it, with their control ids in a ControlId column.

Controls covered: Art. 21(c/e/f/h/i/j)

Official text: Directive (EU) 2022/2555.

cv4pve-diag --host=pve01 --api-token='diag@pve!audit=…' --compliance=Nis2 execute --full
GravityControlIdCodeIdDescriptionContextSubContext
CriticalArt.21(j)CC0004access/users/root@pamroot@pam has no TFA configured — full access protected only by passwordClusterAccess
CriticalArt.21(i)CG0006nodes/pve02/lxc/101Privileged container has AppArmor disabled — no kernel confinement, root inside has unrestricted host accessLxcSecurity
CriticalArt.21(c)CG0002nodes/pve02/qemu/203Disk 'scsi0' disabled for backupQemuBackup
WarningArt.21(e)WN0013nodes/pve01Node requires reboot: running kernel '6.8.12-20-pve' but newer kernel '6.8.12-43-pve' is installedNodeReboot
WarningArt.21(e)WG0037nodes/pve01/qemu/1010CPU type 'kvm64' is missing security flags: +spec-ctrl, +ssbd, +pcid, +md-clear — add to cpu flags to mitigate Spectre/Meltdown/MDSQemuCPU
WarningArt.21(c)WG0017nodes/pve02/qemu/999vzdump backup not configuredQemuBackup
WarningArt.21(e)WG0002nodes/pve01/qemu/1013OS 'Microsoft Windows 8.x/2012/2012r2' not maintained from vendor!QemuOSNotMaintained
InfoArt.21(c)IC0002clusterNo HA resources configured — VMs will not automatically restart on node failureClusterHA
OkArt.21(c)WC0001cluster/backup3 backup job(s) configured at cluster levelClusterBackup
OkArt.21(e)WC0003clusterCluster firewall is enabledClusterFirewall
OkArt.21(c)WG0017nodes/pve01/qemu/100Guest is covered by at least one enabled backup jobQemuBackup
OkArt.21(c)WG0017nodes/pve01/qemu/101Guest is covered by at least one enabled backup jobQemuBackup
One row per object: a check failing — or passing — on ten VMs gives ten rows, all the controls of a finding in the same row. Ok rows come from --full, or IncludeOkResult: true in the settings file.

In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.

Article Title Where it appears
Art. 21(c) Backup management and disaster recovery Backup, HA, replication, single-node
Art. 21(e) Vulnerability handling and disclosure Patch, CVE, firewall, OS EOL, CPU security flags
Art. 21(f) Effectiveness assessment (logging / monitoring) Cluster log, task failures, NTP, services, metric server
Art. 21(h) Cryptography and encryption Certificates
Art. 21(i) Access control policies and asset management ACL, container isolation, pools, account lifecycle, tokens
Art. 21(j) Multi-factor authentication TFA (all variants)

How the mapping works, and its limits: Compliance overview.