Skip to content

NIST SP 800-53

NIST SP 800-53 rev.5 — Moderate baseline subset. Run with --compliance=Nist80053 to keep only the findings mapped to it, with their control ids in a ControlId column.

Controls covered: AC-2/3/6, AU-2/6/12, CM-2/6/7, CP-9/10, IA-2/5, SC-7/8/13, SI-2/4/5

Official text: NIST SP 800-53 Rev. 5.

In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.

Subset of NIST 800-53 rev.5 controls verifiable on a Proxmox VE cluster. Families used: AC (Access Control), AU (Audit), CM (Configuration Management), CP (Contingency Planning), IA (Identification and Authentication), SC (System and Communications Protection), SI (System and Information Integrity).

Control Title Where it appears
AC-2 Account management Account lifecycle, user expiration, API token expiration
AC-3 Access enforcement (declared)
AC-6 Least privilege ACL, container privileged, root@pam token privsep
AU-2 Event logging (declared)
AU-6 Audit record review (declared)
AU-12 Audit record generation Cluster log, task history, firewall audit logging, metric server
CM-2 Baseline configuration Patch consistency across nodes, version/kernel mismatch
CM-6 Configuration settings (declared)
CM-7 Least functionality (declared)
CP-9 System backup All backup checks, backup storage availability, disk cache integrity
CP-10 System recovery and reconstitution HA, replication, single-node, HA guest checks
IA-2 Identification and authentication TFA (root@pam, admins, group, realm)
IA-5 Authenticator management (declared — overlaps with certificate / token checks)
SC-7 Boundary protection Cluster/node firewall, guest firewall
SC-8 Transmission confidentiality and integrity Certificates (expired / expiring), TLS
SC-13 Cryptographic protection Certificates
SI-2 Flaw remediation Patch, PVE EOL, CVE, important updates, outdated machine type
SI-4 System monitoring Cluster log, task history, firewall audit logging, services, NTP, user notifications, metric server
SI-5 Security alerts and advisories CVE

How the mapping works, and its limits: Compliance overview.