NIS2
NIS2 — Art. 21. Run with --compliance=Nis2 to keep only the findings mapped to it, with their control ids in a ControlId column.
Controls covered: Art. 21(c/e/f/h/i/j)
Official text: Directive (EU) 2022/2555.
| Gravity | ControlId | Code | Id | Description | Context | SubContext |
|---|---|---|---|---|---|---|
| Critical | Art.21(j) | CC0004 | access/users/root@pam | root@pam has no TFA configured — full access protected only by password | Cluster | Access |
| Critical | Art.21(i) | CG0006 | nodes/pve02/lxc/101 | Privileged container has AppArmor disabled — no kernel confinement, root inside has unrestricted host access | Lxc | Security |
| Critical | Art.21(c) | CG0002 | nodes/pve02/qemu/203 | Disk 'scsi0' disabled for backup | Qemu | Backup |
| Warning | Art.21(e) | WN0013 | nodes/pve01 | Node requires reboot: running kernel '6.8.12-20-pve' but newer kernel '6.8.12-43-pve' is installed | Node | Reboot |
| Warning | Art.21(e) | WG0037 | nodes/pve01/qemu/1010 | CPU type 'kvm64' is missing security flags: +spec-ctrl, +ssbd, +pcid, +md-clear — add to cpu flags to mitigate Spectre/Meltdown/MDS | Qemu | CPU |
| Warning | Art.21(c) | WG0017 | nodes/pve02/qemu/999 | vzdump backup not configured | Qemu | Backup |
| Warning | Art.21(e) | WG0002 | nodes/pve01/qemu/1013 | OS 'Microsoft Windows 8.x/2012/2012r2' not maintained from vendor! | Qemu | OSNotMaintained |
| Info | Art.21(c) | IC0002 | cluster | No HA resources configured — VMs will not automatically restart on node failure | Cluster | HA |
| Ok | Art.21(c) | WC0001 | cluster/backup | 3 backup job(s) configured at cluster level | Cluster | Backup |
| Ok | Art.21(e) | WC0003 | cluster | Cluster firewall is enabled | Cluster | Firewall |
| Ok | Art.21(c) | WG0017 | nodes/pve01/qemu/100 | Guest is covered by at least one enabled backup job | Qemu | Backup |
| Ok | Art.21(c) | WG0017 | nodes/pve01/qemu/101 | Guest is covered by at least one enabled backup job | Qemu | Backup |
One row per object: a check failing — or passing — on ten VMs gives ten rows, all the controls of a finding in the same row.
Ok rows come from --full, or IncludeOkResult: true in the settings file.Controls
Section titled “Controls”In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.
| Article | Title | Where it appears |
|---|---|---|
| Art. 21(c) | Backup management and disaster recovery | Backup, HA, replication, single-node |
| Art. 21(e) | Vulnerability handling and disclosure | Patch, CVE, firewall, OS EOL, CPU security flags |
| Art. 21(f) | Effectiveness assessment (logging / monitoring) | Cluster log, task failures, NTP, services, metric server |
| Art. 21(h) | Cryptography and encryption | Certificates |
| Art. 21(i) | Access control policies and asset management | ACL, container isolation, pools, account lifecycle, tokens |
| Art. 21(j) | Multi-factor authentication | TFA (all variants) |
How the mapping works, and its limits: Compliance overview.