feat: reflect netOrk v0.4.0 features (MFA, config backup, ack warnings)
CI / TypeScript — type-check (push) Successful in 9s
CI / Publish — build & push image (push) Successful in 8s
CI / Deploy — pull & restart on host (push) Successful in 2s

Moves MFA/TOTP and config backup & versioning from roadmap to shipped
across the NIS2 coverage page, features list, and roadmap, and adds a
homepage screenshot row for the new config snapshot/diff/restore UI.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Christian Manivong
2026-06-30 13:23:37 +02:00
co-authored by Claude Sonnet 4.6
parent 77a73030b4
commit 2f8cbf48af
6 changed files with 96 additions and 31 deletions
+9 -2
View File
@@ -147,6 +147,15 @@ Each badge uses the `Driver / Integration Badge` component from DESIGN.md.
agent is missing. Graylog syslog forwarding status with auto-fix.`
- Screenshot: SecurityTab inside DeviceDetailPage
**Row 4 — Right text, left screenshot**
- Heading: `Configuration backup and versioning`
- Copy: `Every poll captures a config snapshot into a local Git
repository. The Config tab shows the full snapshot history, a
side-by-side diff between any two points in time, and — for
OPNsense — a Restore button. Unauthorized changes show up as a
device warning.`
- Screenshot: ConfigTab inside DeviceDetailPage
---
### Section 5b — NIS2
@@ -330,7 +339,6 @@ address NIS2 Art. 21 technical baseline requirements.
**Planned items (NIS2-tagged):**
- CVE tracking per device — NVD / OSV cross-reference
- Configuration backup & versioning — git-backed snapshots, change detection
- Compliance dashboard — per-site Art. 21 checklist view
- Audit log export — PDF / CSV with filters
@@ -342,7 +350,6 @@ address NIS2 Art. 21 technical baseline requirements.
**Under consideration (NIS2-tagged):**
- Incident workflow — structured record + NIS2 Art. 23 Fristen-Tracker
- EOL tracking — endoflife.date integration for firmware / OS
- MFA (TOTP) — second factor for netOrk logins
**Under consideration (general):**
- mDNS scanner — media device discovery
+13 -1
View File
@@ -68,7 +68,8 @@ hardware and want operational visibility beyond what consumer dashboards offer.
9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch
management, access control, and audit trails. netOrk produces all of these as
day-to-day operational outputs: full device inventory, per-device update status,
Wazuh CVE tracking, RBAC, config drift detection, and a complete audit log.
Wazuh CVE tracking, RBAC with MFA, Git-backed config snapshots with diff/restore,
config drift detection, and a complete audit log.
---
@@ -120,6 +121,11 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- One-click drift fix stream with live SSH output in the browser
- UCI-based config push for OpenWRT (VLAN names, SSID settings, radio config)
- AP profile system: country code, HT/VHT mode, 802.11r, NTP, syslog, SSH port
- Configuration backup & versioning: every poll captures a config snapshot into
a local Git repository, with full history and a side-by-side diff viewer
between any two points in time
- One-click config restore for OPNsense from any prior snapshot
- Unauthorised configuration changes are surfaced as a device warning
### Scheduled Operations
- Scheduled reboots for OpenWRT APs with per-site concurrency lock
@@ -130,6 +136,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
### Monitoring & Health
- SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()`
- Per-device warning system with severity levels (error / warning / info)
- One-click Ack on any warning — clears it immediately and writes an audit log
entry; for config-change warnings the current state is accepted as the new
baseline
- Docker container and image status (Proxmox/Linux)
- Service status and start/stop/restart (systemd)
- VM/container list with OS device cross-linking (Proxmox)
@@ -148,6 +157,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
### Access Control
- JWT authentication with remember-me (localStorage) or session-only (sessionStorage)
- Two-factor authentication (MFA/TOTP) — authenticator app at login, backup
codes for emergencies, session invalidation on TOTP changes, enforceable
per role
- RBAC with four built-in roles: viewer / operator / engineer / administrator
- Custom roles with any permission combination
- Full audit log of all orchestration actions
+22
View File
@@ -63,6 +63,10 @@ const en = {
heading: 'Security visibility per device',
body: 'Wazuh agent status, CVE counts by severity, and recent alerts — all linked to the device record. One-click agent install if the agent is missing. Graylog syslog forwarding status with auto-fix.',
},
screenshot4: {
heading: 'Configuration backup and versioning',
body: 'Every poll captures a config snapshot into a local Git repository. The Config tab shows the full snapshot history, a side-by-side diff between any two points in time, and — for OPNsense — a Restore button. Unauthorized changes show up as a device warning.',
},
nis2Label: 'NIS2 · Art. 21',
nis2Heading: 'Evidence, not paperwork.',
nis2Body: "NIS2 Art. 21 mandates asset inventory, patch management, access control, and audit trails as baseline technical measures. netOrk doesn't bolt on a compliance layer — these are its day-to-day outputs.",
@@ -141,6 +145,9 @@ const en = {
'One-click drift fix stream with live SSH output in the browser',
'UCI-based config push for OpenWRT (VLAN names, SSID settings, radio config)',
'AP profile system: country code, HT/VHT mode, 802.11r, NTP, syslog, SSH port',
'Configuration backup & versioning: every poll snapshots config into a local Git repo, with full history and a side-by-side diff viewer',
'One-click config restore for OPNsense from any prior snapshot',
'Unauthorized configuration changes are surfaced as a device warning',
],
},
{
@@ -157,6 +164,7 @@ const en = {
items: [
'SNMP health metrics (CPU, memory, interface counters) via get_health_metrics()',
'Per-device warning system with severity levels (error / warning / info)',
'One-click Ack on any warning — clears it immediately and logs the action; config-change warnings accept the current state as the new baseline',
'Docker container and image status (Proxmox/Linux)',
'Service status and start/stop/restart (systemd)',
'VM/container list with OS device cross-linking (Proxmox)',
@@ -183,6 +191,7 @@ const en = {
title: 'Access Control (RBAC)',
items: [
'JWT authentication with remember-me (localStorage) or session-only (sessionStorage)',
'Two-factor authentication (MFA/TOTP): authenticator app at login, backup codes, session invalidation on TOTP changes, enforceable per role',
'RBAC with four built-in roles: viewer / operator / engineer / administrator',
'Custom roles with any permission combination',
'Full audit log of all orchestration actions',
@@ -200,9 +209,11 @@ const en = {
title: 'Compliance & Audit (NIS2)',
items: [
'Full audit log of all orchestration actions — who changed what, when (Art. 21 (2h))',
'Two-factor authentication (MFA/TOTP), enforceable per role — administrative access control (Art. 21 (2i))',
'RBAC with four built-in roles and custom permission sets — access control evidence',
'Per-device patch status and installed package list — patch management baseline (Art. 21 (2e))',
'Wazuh CVE counts by severity (critical / high / medium) linked to each device record',
'Git-backed configuration snapshot history with diff viewer and OPNsense restore — config-level backup & recovery evidence (Art. 21 (2c))',
'Config drift tracking: desired state vs. polled state — detect unauthorized changes',
'Security agent coverage report: which devices have Wazuh, Graylog, CrowdSec active',
'SNMP health metrics as continuous monitoring baseline (Art. 21 (2a))',
@@ -335,6 +346,10 @@ const de: Translations = {
heading: 'Sicherheitssichtbarkeit pro Gerät',
body: 'Wazuh-Agent-Status, CVE-Anzahl nach Schweregrad und aktuelle Alerts — alle mit dem Gerätedatensatz verknüpft. Ein-Klick-Agent-Installation falls der Agent fehlt. Graylog-Syslog-Weiterleitungsstatus mit Auto-Fix.',
},
screenshot4: {
heading: 'Konfigurationsbackup und -versionierung',
body: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert. Der Config-Tab zeigt die vollständige Snapshot-Historie, einen Side-by-Side-Diff zwischen beliebigen Zeitpunkten und — für OPNsense — einen Restore-Button. Nicht autorisierte Änderungen erscheinen als Gerätewarnung.',
},
nis2Label: 'NIS2 · Art. 21',
nis2Heading: 'Nachweise, keine Papierwüste.',
nis2Body: 'NIS2 Art. 21 schreibt Geräteinventar, Patch-Management, Zugangskontrolle und Audit-Trails als technische Basismaßnahmen vor. netOrk fügt keine Compliance-Schicht auf — das sind seine normalen Tagesausgaben.',
@@ -413,6 +428,9 @@ const de: Translations = {
'Ein-Klick-Drift-Fix-Stream mit Live-SSH-Output im Browser',
'UCI-basierter Config-Push für OpenWRT (VLAN-Namen, SSID-Einstellungen, Radio-Konfiguration)',
'AP-Profil-System: Ländercode, HT/VHT-Modus, 802.11r, NTP, Syslog, SSH-Port',
'Konfigurationsbackup & -versionierung: bei jedem Poll wird ein Snapshot in ein lokales Git-Repository geschrieben — vollständige Historie und Side-by-Side-Diff-Viewer',
'Ein-Klick-Konfigurations-Restore für OPNsense aus jedem früheren Snapshot',
'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt',
],
},
{
@@ -429,6 +447,7 @@ const de: Translations = {
items: [
'SNMP-Gesundheitsmetriken (CPU, Speicher, Schnittstellenzähler) via get_health_metrics()',
'Gerätespezifisches Warnsystem mit Schweregraden (Fehler / Warnung / Info)',
'Ein-Klick-Ack für jede Warnung — löscht sie sofort und protokolliert die Aktion; bei Config-Change-Warnungen wird der aktuelle Zustand als neue Baseline akzeptiert',
'Docker-Container- und Image-Status (Proxmox/Linux)',
'Service-Status und Start/Stop/Neustart (systemd)',
'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)',
@@ -455,6 +474,7 @@ const de: Translations = {
title: 'Zugangskontrolle (RBAC)',
items: [
'JWT-Authentifizierung mit Remember-Me (localStorage) oder nur Sitzung (sessionStorage)',
'Zwei-Faktor-Authentifizierung (MFA/TOTP): Authenticator-App beim Login, Backup-Codes, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar',
'RBAC mit vier integrierten Rollen: Betrachter / Operator / Ingenieur / Administrator',
'Benutzerdefinierte Rollen mit beliebiger Berechtigungskombination',
'Vollständiges Audit-Log aller Orchestrierungsaktionen',
@@ -472,9 +492,11 @@ const de: Translations = {
title: 'Compliance & Audit (NIS2)',
items: [
'Vollständiges Audit-Log aller Orchestrierungsaktionen — wer hat was wann geändert (Art. 21 (2h))',
'Zwei-Faktor-Authentifizierung (MFA/TOTP), pro Rolle erzwingbar — Zugangskontrolle für administrative Konten (Art. 21 (2i))',
'RBAC mit vier integrierten Rollen und benutzerdefinierten Berechtigungssätzen — Zugangskontrollnachweis',
'Patch-Status und installierte Paketliste pro Gerät — Patch-Management-Baseline (Art. 21 (2e))',
'Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) verknüpft mit jedem Gerätedatensatz',
'Git-basierte Konfigurationssnapshot-Historie mit Diff-Viewer und OPNsense-Restore — Backup- & Recovery-Nachweis auf Konfigurationsebene (Art. 21 (2c))',
'Konfigurationsdrift-Tracking: Sollzustand vs. abgefragter Zustand — nicht autorisierte Änderungen erkennen',
'Security-Agent-Abdeckungsbericht: welche Geräte haben Wazuh, Graylog, CrowdSec aktiv',
'SNMP-Gesundheitsmetriken als kontinuierliche Monitoring-Baseline (Art. 21 (2a))',
+42
View File
@@ -165,6 +165,39 @@ function MockVlans() {
)
}
function MockConfigDiff() {
const snapshots = [
{ id: 'a3f9c1', when: '2 min ago', label: 'current' },
{ id: '7e2b04', when: '1 h ago' },
{ id: 'd819e6', when: '6 h ago' },
]
return (
<div className="bg-slate-950 p-4">
<div className="mb-3 flex items-center justify-between">
<span className="text-xs font-semibold text-slate-100">Config — fw-001.lan</span>
<button className="text-xs px-2.5 py-1 rounded bg-sky-600 hover:bg-sky-500 text-white transition-colors">Restore</button>
</div>
<div className="flex gap-2 mb-3">
{snapshots.map((s) => (
<span key={s.id} className={`text-xs font-mono px-2 py-1 rounded border ${s.label ? 'border-sky-500/40 bg-sky-500/10 text-sky-400' : 'border-slate-800 text-slate-500'}`}>
{s.id} <span className="text-slate-600">· {s.when}</span>
</span>
))}
</div>
<div className="rounded-lg border border-slate-800 overflow-hidden font-mono text-xs">
<div className="px-3 py-1.5 bg-slate-900 text-slate-500 border-b border-slate-800">7e2b04 → a3f9c1</div>
<div className="px-3 py-1 bg-red-500/10 text-red-400">- set firewall.rule_42.destination_port='22'</div>
<div className="px-3 py-1 bg-green-500/10 text-green-400">+ set firewall.rule_42.destination_port='2222'</div>
<div className="px-3 py-1 text-slate-500"> commit</div>
</div>
<div className="mt-3 rounded-lg border border-yellow-500/30 bg-yellow-500/10 p-3">
<p className="text-xs text-yellow-400 font-medium">Unauthorized change detected — fw-001.lan</p>
<p className="text-xs text-slate-400 mt-1">Configuration changed outside netOrk between the last two polls.</p>
</div>
</div>
)
}
function MockCompliance() {
const checks = [
{ label: 'Asset inventory', detail: '18 / 18 devices tracked', ok: true },
@@ -375,6 +408,15 @@ export default function Home() {
<MockSecurity />
</BrowserFrame>
</div>
<div className="grid md:grid-cols-2 gap-12 items-center">
<BrowserFrame label="netork.local / devices / fw-001 / config">
<MockConfigDiff />
</BrowserFrame>
<div>
<h2 className="text-2xl md:text-3xl font-bold text-slate-100 mb-4">{h.screenshot4.heading}</h2>
<p className="text-base text-slate-400 leading-relaxed">{h.screenshot4.body}</p>
</div>
</div>
</div>
</section>
+10 -8
View File
@@ -11,25 +11,25 @@ const REQUIREMENTS: Record<'en' | 'de', Requirement[]> = {
en: [
{ article: 'Art. 21 (2a)', label: 'Risk analysis & information system security policies', coverage: 'partial', netork: 'Config drift detection, SNMP health metrics, and security agent coverage across all devices provide a continuous risk baseline. A formal risk register is out of scope for netOrk.' },
{ article: 'Art. 21 (2b)', label: 'Incident handling', coverage: 'partial', netork: 'Wazuh alert history, CrowdSec decisions, and Graylog syslog per device surface incidents at the network layer. A structured incident record with NIS2 Art. 23 reporting timers is on the roadmap.' },
{ article: 'Art. 21 (2c)', label: 'Business continuity, backup management, disaster recovery', coverage: 'roadmap', netork: 'Git-backed configuration snapshots (on roadmap) provide config-level recovery. Backup monitoring for individual devices is not yet implemented.' },
{ article: 'Art. 21 (2c)', label: 'Business continuity, backup management, disaster recovery', coverage: 'partial', netork: 'Every poll captures a configuration snapshot into a local Git repository — full history, a side-by-side diff viewer between any two points in time, and one-click restore for OPNsense. Backup/recovery for full device state beyond configuration is out of scope.' },
{ article: 'Art. 21 (2d)', label: 'Supply chain security', coverage: 'partial', netork: 'Vendor, model, firmware, and OS version are tracked per device after every poll. EOL tracking against endoflife.date is on the roadmap to flag unsupported software.' },
{ article: 'Art. 21 (2e)', label: 'Vulnerability handling in acquisition, development & maintenance', coverage: 'covered', netork: 'Per-device update status and installed package list tracked on every poll. Wazuh CVE counts by severity (critical / high / medium) linked directly to each device record. CVE cross-reference against NVD/OSV (without Wazuh) is on the roadmap.' },
{ article: 'Art. 21 (2f)', label: 'Assessing effectiveness of cybersecurity measures', coverage: 'partial', netork: 'The audit log records all orchestration actions. A per-site compliance dashboard (on roadmap) will aggregate security agent coverage, drift status, and patch metrics into a single view.' },
{ article: 'Art. 21 (2g)', label: 'Basic cyber hygiene & cybersecurity training', coverage: 'na', netork: 'Out of scope for a network orchestration platform. Training and hygiene policies are handled at the organizational level.' },
{ article: 'Art. 21 (2h)', label: 'Access control, asset management, human resources security', coverage: 'covered', netork: 'Full device inventory maintained automatically via discovery and continuous polling. RBAC with four built-in roles (viewer / operator / engineer / administrator) and custom role combinations. Complete audit log of all orchestration actions.' },
{ article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'roadmap', netork: 'TOTP-based MFA for netOrk user accounts is on the roadmap. Current authentication is JWT-based (username + password).' },
{ article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'covered', netork: 'TOTP-based MFA for netOrk user accounts — authenticator app at login, backup codes for emergencies, session invalidation on TOTP changes, enforceable per role.' },
{ article: 'Art. 21 (2j)', label: 'Physical and environmental security', coverage: 'na', netork: 'Out of scope. Physical security of the infrastructure hosting netOrk is an organizational and facility concern.' },
],
de: [
{ article: 'Art. 21 (2a)', label: 'Risikoanalyse und Sicherheitsrichtlinien für Informationssysteme', coverage: 'partial', netork: 'Konfigurationsdrift-Erkennung, SNMP-Gesundheitsmetriken und Security-Agent-Abdeckung über alle Geräte liefern eine kontinuierliche Risiko-Baseline. Ein formales Risikoregister liegt außerhalb des Scopes von netOrk.' },
{ article: 'Art. 21 (2b)', label: 'Bewältigung von Sicherheitsvorfällen', coverage: 'partial', netork: 'Wazuh-Alert-Historie, CrowdSec-Entscheidungen und Graylog-Syslog pro Gerät decken Vorfälle auf Netzwerkebene auf. Ein strukturierter Incident-Datensatz mit NIS2 Art. 23 Melde-Timern ist auf der Roadmap.' },
{ article: 'Art. 21 (2c)', label: 'Geschäftskontinuität, Backup-Management, Disaster Recovery', coverage: 'roadmap', netork: 'Git-basierte Konfigurationssnapshots (auf der Roadmap) ermöglichen Wiederherstellung auf Konfigurationsebene. Backup-Monitoring für einzelne Geräte ist noch nicht implementiert.' },
{ article: 'Art. 21 (2c)', label: 'Geschäftskontinuität, Backup-Management, Disaster Recovery', coverage: 'partial', netork: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert — vollständige Historie, ein Side-by-Side-Diff-Viewer zwischen beliebigen Zeitpunkten und Ein-Klick-Restore für OPNsense. Backup/Recovery für den vollständigen Gerätezustand über die Konfiguration hinaus liegt außerhalb des Scopes.' },
{ article: 'Art. 21 (2d)', label: 'Supply-Chain-Sicherheit', coverage: 'partial', netork: 'Hersteller, Modell, Firmware und OS-Version werden nach jedem Poll pro Gerät erfasst. EOL-Tracking über endoflife.date ist auf der Roadmap, um nicht unterstützte Software zu kennzeichnen.' },
{ article: 'Art. 21 (2e)', label: 'Schwachstellenbehandlung bei Erwerb, Entwicklung & Wartung', coverage: 'covered', netork: 'Update-Status und installierte Paketliste pro Gerät werden bei jedem Poll erfasst. Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) direkt mit jedem Gerätedatensatz verknüpft. CVE-Abgleich gegen NVD/OSV (ohne Wazuh) ist auf der Roadmap.' },
{ article: 'Art. 21 (2f)', label: 'Beurteilung der Wirksamkeit von Cybersicherheitsmaßnahmen', coverage: 'partial', netork: 'Das Audit-Log erfasst alle Orchestrierungsaktionen. Ein Compliance-Dashboard pro Standort (auf der Roadmap) wird Security-Agent-Abdeckung, Drift-Status und Patch-Metriken in einer Ansicht zusammenfassen.' },
{ article: 'Art. 21 (2g)', label: 'Grundlegende Cyberhygiene und Cybersicherheitsschulungen', coverage: 'na', netork: 'Außerhalb des Scopes einer Netzwerk-Orchestrierungsplattform. Schulungen und Hygiene-Richtlinien werden auf Organisationsebene gehandhabt.' },
{ article: 'Art. 21 (2h)', label: 'Zugangskontrolle, Asset-Management, Personalsicherheit', coverage: 'covered', netork: 'Vollständiges Geräteinventar automatisch über Discovery und kontinuierliches Polling gepflegt. RBAC mit vier integrierten Rollen (Betrachter / Operator / Ingenieur / Administrator) und benutzerdefinierten Rollenkombinationen. Vollständiges Audit-Log aller Orchestrierungsaktionen.' },
{ article: 'Art. 21 (2i)', label: 'Multi-Faktor-Authentifizierung', coverage: 'roadmap', netork: 'TOTP-basierte MFA für netOrk-Benutzerkonten ist auf der Roadmap. Die aktuelle Authentifizierung ist JWT-basiert (Benutzername + Passwort).' },
{ article: 'Art. 21 (2i)', label: 'Multi-Faktor-Authentifizierung', coverage: 'covered', netork: 'TOTP-basierte MFA für netOrk-Benutzerkonten — Authenticator-App beim Login, Backup-Codes für Notfälle, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar.' },
{ article: 'Art. 21 (2j)', label: 'Physische und umgebungsbezogene Sicherheit', coverage: 'na', netork: 'Außerhalb des Scopes. Die physische Sicherheit der Infrastruktur, die netOrk hostet, ist eine organisatorische und gebäudetechnische Angelegenheit.' },
],
}
@@ -47,6 +47,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
'Wazuh agent status and CVE counts by severity',
'Graylog syslog forwarding status',
'CrowdSec decisions and ban counts',
'Git-backed configuration snapshot, diffed against the previous one to detect unauthorized changes',
],
},
{
@@ -54,6 +55,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
produces: [
'Audit log entry: user, timestamp, resource, action',
'Before/after values for configuration changes',
'Acknowledged warnings logged with the accepting user',
],
},
{
@@ -62,6 +64,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
'Topology graph — network segmentation view',
'Subnet browser — IP space coverage',
'VLAN matrix — which devices carry which VLANs',
'Configuration diff between any two snapshots; one-click restore (OPNsense)',
'Audit log export to PDF / CSV (roadmap)',
],
},
@@ -78,6 +81,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
'Wazuh-Agent-Status und CVE-Anzahl nach Schweregrad',
'Graylog-Syslog-Weiterleitungsstatus',
'CrowdSec-Entscheidungen und Ban-Anzahl',
'Git-basierter Konfigurationssnapshot, gegen den vorherigen geprüft, um nicht autorisierte Änderungen zu erkennen',
],
},
{
@@ -85,6 +89,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
produces: [
'Audit-Log-Eintrag: Benutzer, Zeitstempel, Ressource, Aktion',
'Vorher/Nachher-Werte für Konfigurationsänderungen',
'Bestätigte (acked) Warnungen werden mit dem bestätigenden Benutzer protokolliert',
],
},
{
@@ -93,6 +98,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
'Topologie-Graph — Netzwerksegmentierungs-Ansicht',
'Subnetz-Browser — IP-Raum-Abdeckung',
'VLAN-Matrix — welche Geräte welche VLANs führen',
'Konfigurations-Diff zwischen zwei beliebigen Snapshots; Ein-Klick-Restore (OPNsense)',
'Audit-Log-Export als PDF / CSV (Roadmap)',
],
},
@@ -102,21 +108,17 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
const COMING: Record<'en' | 'de', ComingItem[]> = {
en: [
{ title: 'CVE tracking per device', detail: 'Automatic cross-reference of installed packages against NVD / OSV — no Wazuh agent required.' },
{ title: 'Configuration backup & versioning', detail: 'Git-backed config snapshots after every poll. Detect unauthorized changes, compare over time.' },
{ title: 'Compliance dashboard', detail: 'Per-site Art. 21 checklist: asset coverage, patch status, agent deployment, drift, syslog, audit activity.' },
{ title: 'Audit log export', detail: 'PDF and CSV export filtered by date range, device, user, or action — ready to hand to an auditor.' },
{ title: 'Incident workflow', detail: 'Structured incident records with NIS2 Art. 23 reporting timers (24 h / 72 h) and external webhook delivery.' },
{ title: 'EOL tracking', detail: 'Flag devices running end-of-life firmware or OS versions via the endoflife.date API.' },
{ title: 'MFA (TOTP)', detail: 'Time-based one-time passwords as a second factor for netOrk user accounts (Art. 21 (2i)).' },
],
de: [
{ title: 'CVE-Tracking pro Gerät', detail: 'Automatischer Abgleich installierter Pakete gegen NVD / OSV — kein Wazuh-Agent erforderlich.' },
{ title: 'Konfigurationsbackup & -versionierung', detail: 'Git-basierte Konfigurationssnapshots nach jedem Poll. Nicht autorisierte Änderungen erkennen, über die Zeit vergleichen.' },
{ title: 'Compliance-Dashboard', detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Agent-Deployment, Drift, Syslog, Audit-Aktivität.' },
{ title: 'Audit-Log-Export', detail: 'PDF- und CSV-Export gefiltert nach Datumsbereich, Gerät, Benutzer oder Aktion — bereit zur Übergabe an einen Prüfer.' },
{ title: 'Incident-Workflow', detail: 'Strukturierte Incident-Datensätze mit NIS2 Art. 23 Melde-Timern (24 h / 72 h) und externer Webhook-Zustellung.' },
{ title: 'EOL-Tracking', detail: 'Geräte mit End-of-Life-Firmware oder OS-Versionen über die endoflife.date-API kennzeichnen.' },
{ title: 'MFA (TOTP)', detail: 'Zeitbasierte Einmalpasswörter als zweiter Faktor für netOrk-Benutzerkonten (Art. 21 (2i)).' },
],
}
-20
View File
@@ -13,11 +13,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
detail: 'Cross-reference installed packages and OS versions against NVD / OSV. Surfaces "this device has 3 unpatched CVEs (CVSS ≥ 7)" without leaving netOrk.',
nis2: true,
},
{
title: 'Configuration backup & versioning',
detail: 'Git-backed config snapshots on every poll. Detect unauthorized changes between snapshots and provide rollback targets.',
nis2: true,
},
{
title: 'Compliance dashboard',
detail: 'Per-site Art. 21 checklist: asset coverage, patch status, security agent deployment, config drift, syslog forwarding, audit activity — aggregated into a single view.',
@@ -55,11 +50,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
detail: 'Flag devices running end-of-life software via the endoflife.date API. Covers OPNsense, OpenWRT, Debian, Ubuntu, and more — matched to the OS versions netOrk already polls.',
nis2: true,
},
{
title: 'MFA (TOTP) for netOrk login',
detail: 'Time-based one-time passwords as a second factor for netOrk user accounts. Directly covers NIS2 Art. 21 (2i) MFA requirement for administrative access.',
nis2: true,
},
{
title: 'mDNS scanner',
detail: 'Discover media devices (Apple TV, Chromecast, Sonos) via mDNS/Bonjour without needing a NAPALM driver. Inventory visibility and firewall segmentation suggestions.',
@@ -84,11 +74,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
detail: 'CVE-Abgleich mit installierten Paketen und OS-Versionen über NVD / OSV. Zeigt „Dieses Gerät hat 3 ungepatchte CVEs (CVSS ≥ 7)" direkt in netOrk an.',
nis2: true,
},
{
title: 'Konfigurationsbackup & -versionierung',
detail: 'Git-basierte Konfigurationssnapshots bei jedem Poll. Erkennt nicht autorisierte Änderungen zwischen Snapshots und bietet Rollback-Ziele.',
nis2: true,
},
{
title: 'Compliance-Dashboard',
detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Security-Agent-Deployment, Config-Drift, Syslog-Weiterleitung, Audit-Aktivität — zusammengefasst in einer Ansicht.',
@@ -126,11 +111,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
detail: 'Markiert Geräte mit End-of-Life-Software über die endoflife.date-API. Deckt OPNsense, OpenWRT, Debian, Ubuntu und weitere ab — abgeglichen mit den OS-Versionen, die netOrk bereits abfragt.',
nis2: true,
},
{
title: 'MFA (TOTP) für netOrk-Login',
detail: 'Zeitbasierte Einmalpasswörter als zweiter Faktor für netOrk-Benutzerkonten. Deckt direkt NIS2 Art. 21 (2i) MFA-Anforderung für administrativen Zugang ab.',
nis2: true,
},
{
title: 'mDNS-Scanner',
detail: 'Entdeckt Mediengeräte (Apple TV, Chromecast, Sonos) über mDNS/Bonjour ohne NAPALM-Treiber. Inventarsichtbarkeit und Empfehlungen zur Firewall-Segmentierung.',