Skip to content

SOC 2

SOC 2 — AICPA Trust Services Criteria (2017 + 2022 revision). Run with --compliance=Soc2 to keep only the findings mapped to it, with their control ids in a ControlId column.

Controls covered: CC6.1/2/3/6/7/8, CC7.1/2/3, CC8.1, A1.1/2/3, C1.1/2

Official text: SOC 2.

In the tables below, Where it appears names the checks that carry the control. (declared) marks a control of the standard that is relevant to a virtualisation cluster but that no check can verify from the Proxmox VE API — typically a process, a plan or a test. It is listed so the coverage is explicit: evidence for it has to come from outside cv4pve-diag.

Subset of TSC criteria verifiable on a Proxmox VE cluster. Categories: CC = Common Criteria, A = Availability, C = Confidentiality.

Control Title Where it appears
CC6.1 Logical access security TFA (root@pam, admins, group, realm)
CC6.2 Authentication and authorization Account lifecycle, user expiration, API token expiration
CC6.3 Access request authorization ACL, container privileged, root@pam token privsep
CC6.6 Boundary protection Cluster/node firewall, guest firewall, malware-defence baseline
CC6.7 Information transmission controls Certificates (expired / expiring), TLS
CC6.8 Malicious software prevention (declared — overlaps with patch/firewall checks)
CC7.1 Vulnerability and configuration monitoring Patch, PVE EOL, CVE, important updates, outdated machine type
CC7.2 System monitoring Cluster log, task history, firewall audit logging, metric server (IC0018/IC0019)
CC7.3 Security event evaluation (declared)
CC8.1 Change management Patch consistency across nodes, version/kernel mismatch
A1.1 Capacity planning HA, single-node, container isolation
A1.2 Backup and recovery infrastructure HA, replication, single-node, all backup checks
A1.3 Recovery plan testing (declared)
C1.1 Confidential information management (declared — overlaps with backup/PII checks)
C1.2 Confidential information disposal (declared)

How the mapping works, and its limits: Compliance overview.