diff --git a/docs/PAGES.md b/docs/PAGES.md index edce3c1..02e2c9b 100644 --- a/docs/PAGES.md +++ b/docs/PAGES.md @@ -147,6 +147,15 @@ Each badge uses the `Driver / Integration Badge` component from DESIGN.md. agent is missing. Graylog syslog forwarding status with auto-fix.` - Screenshot: SecurityTab inside DeviceDetailPage +**Row 4 — Right text, left screenshot** +- Heading: `Configuration backup and versioning` +- Copy: `Every poll captures a config snapshot into a local Git + repository. The Config tab shows the full snapshot history, a + side-by-side diff between any two points in time, and — for + OPNsense — a Restore button. Unauthorized changes show up as a + device warning.` +- Screenshot: ConfigTab inside DeviceDetailPage + --- ### Section 5b — NIS2 @@ -330,7 +339,6 @@ address NIS2 Art. 21 technical baseline requirements. **Planned items (NIS2-tagged):** - CVE tracking per device — NVD / OSV cross-reference -- Configuration backup & versioning — git-backed snapshots, change detection - Compliance dashboard — per-site Art. 21 checklist view - Audit log export — PDF / CSV with filters @@ -342,7 +350,6 @@ address NIS2 Art. 21 technical baseline requirements. **Under consideration (NIS2-tagged):** - Incident workflow — structured record + NIS2 Art. 23 Fristen-Tracker - EOL tracking — endoflife.date integration for firmware / OS -- MFA (TOTP) — second factor for netOrk logins **Under consideration (general):** - mDNS scanner — media device discovery diff --git a/docs/PRODUCT.md b/docs/PRODUCT.md index a612fc9..a544385 100644 --- a/docs/PRODUCT.md +++ b/docs/PRODUCT.md @@ -68,7 +68,8 @@ hardware and want operational visibility beyond what consumer dashboards offer. 9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch management, access control, and audit trails. netOrk produces all of these as day-to-day operational outputs: full device inventory, per-device update status, - Wazuh CVE tracking, RBAC, config drift detection, and a complete audit log. + Wazuh CVE tracking, RBAC with MFA, Git-backed config snapshots with diff/restore, + config drift detection, and a complete audit log. --- @@ -120,6 +121,11 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju - One-click drift fix stream with live SSH output in the browser - UCI-based config push for OpenWRT (VLAN names, SSID settings, radio config) - AP profile system: country code, HT/VHT mode, 802.11r, NTP, syslog, SSH port +- Configuration backup & versioning: every poll captures a config snapshot into + a local Git repository, with full history and a side-by-side diff viewer + between any two points in time +- One-click config restore for OPNsense from any prior snapshot +- Unauthorised configuration changes are surfaced as a device warning ### Scheduled Operations - Scheduled reboots for OpenWRT APs with per-site concurrency lock @@ -130,6 +136,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju ### Monitoring & Health - SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()` - Per-device warning system with severity levels (error / warning / info) +- One-click Ack on any warning — clears it immediately and writes an audit log + entry; for config-change warnings the current state is accepted as the new + baseline - Docker container and image status (Proxmox/Linux) - Service status and start/stop/restart (systemd) - VM/container list with OS device cross-linking (Proxmox) @@ -148,6 +157,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju ### Access Control - JWT authentication with remember-me (localStorage) or session-only (sessionStorage) +- Two-factor authentication (MFA/TOTP) — authenticator app at login, backup + codes for emergencies, session invalidation on TOTP changes, enforceable + per role - RBAC with four built-in roles: viewer / operator / engineer / administrator - Custom roles with any permission combination - Full audit log of all orchestration actions diff --git a/src/i18n/translations.ts b/src/i18n/translations.ts index 63bd137..70cf07b 100644 --- a/src/i18n/translations.ts +++ b/src/i18n/translations.ts @@ -63,6 +63,10 @@ const en = { heading: 'Security visibility per device', body: 'Wazuh agent status, CVE counts by severity, and recent alerts — all linked to the device record. One-click agent install if the agent is missing. Graylog syslog forwarding status with auto-fix.', }, + screenshot4: { + heading: 'Configuration backup and versioning', + body: 'Every poll captures a config snapshot into a local Git repository. The Config tab shows the full snapshot history, a side-by-side diff between any two points in time, and — for OPNsense — a Restore button. Unauthorized changes show up as a device warning.', + }, nis2Label: 'NIS2 · Art. 21', nis2Heading: 'Evidence, not paperwork.', nis2Body: "NIS2 Art. 21 mandates asset inventory, patch management, access control, and audit trails as baseline technical measures. netOrk doesn't bolt on a compliance layer — these are its day-to-day outputs.", @@ -141,6 +145,9 @@ const en = { 'One-click drift fix stream with live SSH output in the browser', 'UCI-based config push for OpenWRT (VLAN names, SSID settings, radio config)', 'AP profile system: country code, HT/VHT mode, 802.11r, NTP, syslog, SSH port', + 'Configuration backup & versioning: every poll snapshots config into a local Git repo, with full history and a side-by-side diff viewer', + 'One-click config restore for OPNsense from any prior snapshot', + 'Unauthorized configuration changes are surfaced as a device warning', ], }, { @@ -157,6 +164,7 @@ const en = { items: [ 'SNMP health metrics (CPU, memory, interface counters) via get_health_metrics()', 'Per-device warning system with severity levels (error / warning / info)', + 'One-click Ack on any warning — clears it immediately and logs the action; config-change warnings accept the current state as the new baseline', 'Docker container and image status (Proxmox/Linux)', 'Service status and start/stop/restart (systemd)', 'VM/container list with OS device cross-linking (Proxmox)', @@ -183,6 +191,7 @@ const en = { title: 'Access Control (RBAC)', items: [ 'JWT authentication with remember-me (localStorage) or session-only (sessionStorage)', + 'Two-factor authentication (MFA/TOTP): authenticator app at login, backup codes, session invalidation on TOTP changes, enforceable per role', 'RBAC with four built-in roles: viewer / operator / engineer / administrator', 'Custom roles with any permission combination', 'Full audit log of all orchestration actions', @@ -200,9 +209,11 @@ const en = { title: 'Compliance & Audit (NIS2)', items: [ 'Full audit log of all orchestration actions — who changed what, when (Art. 21 (2h))', + 'Two-factor authentication (MFA/TOTP), enforceable per role — administrative access control (Art. 21 (2i))', 'RBAC with four built-in roles and custom permission sets — access control evidence', 'Per-device patch status and installed package list — patch management baseline (Art. 21 (2e))', 'Wazuh CVE counts by severity (critical / high / medium) linked to each device record', + 'Git-backed configuration snapshot history with diff viewer and OPNsense restore — config-level backup & recovery evidence (Art. 21 (2c))', 'Config drift tracking: desired state vs. polled state — detect unauthorized changes', 'Security agent coverage report: which devices have Wazuh, Graylog, CrowdSec active', 'SNMP health metrics as continuous monitoring baseline (Art. 21 (2a))', @@ -335,6 +346,10 @@ const de: Translations = { heading: 'Sicherheitssichtbarkeit pro Gerät', body: 'Wazuh-Agent-Status, CVE-Anzahl nach Schweregrad und aktuelle Alerts — alle mit dem Gerätedatensatz verknüpft. Ein-Klick-Agent-Installation falls der Agent fehlt. Graylog-Syslog-Weiterleitungsstatus mit Auto-Fix.', }, + screenshot4: { + heading: 'Konfigurationsbackup und -versionierung', + body: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert. Der Config-Tab zeigt die vollständige Snapshot-Historie, einen Side-by-Side-Diff zwischen beliebigen Zeitpunkten und — für OPNsense — einen Restore-Button. Nicht autorisierte Änderungen erscheinen als Gerätewarnung.', + }, nis2Label: 'NIS2 · Art. 21', nis2Heading: 'Nachweise, keine Papierwüste.', nis2Body: 'NIS2 Art. 21 schreibt Geräteinventar, Patch-Management, Zugangskontrolle und Audit-Trails als technische Basismaßnahmen vor. netOrk fügt keine Compliance-Schicht auf — das sind seine normalen Tagesausgaben.', @@ -413,6 +428,9 @@ const de: Translations = { 'Ein-Klick-Drift-Fix-Stream mit Live-SSH-Output im Browser', 'UCI-basierter Config-Push für OpenWRT (VLAN-Namen, SSID-Einstellungen, Radio-Konfiguration)', 'AP-Profil-System: Ländercode, HT/VHT-Modus, 802.11r, NTP, Syslog, SSH-Port', + 'Konfigurationsbackup & -versionierung: bei jedem Poll wird ein Snapshot in ein lokales Git-Repository geschrieben — vollständige Historie und Side-by-Side-Diff-Viewer', + 'Ein-Klick-Konfigurations-Restore für OPNsense aus jedem früheren Snapshot', + 'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt', ], }, { @@ -429,6 +447,7 @@ const de: Translations = { items: [ 'SNMP-Gesundheitsmetriken (CPU, Speicher, Schnittstellenzähler) via get_health_metrics()', 'Gerätespezifisches Warnsystem mit Schweregraden (Fehler / Warnung / Info)', + 'Ein-Klick-Ack für jede Warnung — löscht sie sofort und protokolliert die Aktion; bei Config-Change-Warnungen wird der aktuelle Zustand als neue Baseline akzeptiert', 'Docker-Container- und Image-Status (Proxmox/Linux)', 'Service-Status und Start/Stop/Neustart (systemd)', 'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)', @@ -455,6 +474,7 @@ const de: Translations = { title: 'Zugangskontrolle (RBAC)', items: [ 'JWT-Authentifizierung mit Remember-Me (localStorage) oder nur Sitzung (sessionStorage)', + 'Zwei-Faktor-Authentifizierung (MFA/TOTP): Authenticator-App beim Login, Backup-Codes, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar', 'RBAC mit vier integrierten Rollen: Betrachter / Operator / Ingenieur / Administrator', 'Benutzerdefinierte Rollen mit beliebiger Berechtigungskombination', 'Vollständiges Audit-Log aller Orchestrierungsaktionen', @@ -472,9 +492,11 @@ const de: Translations = { title: 'Compliance & Audit (NIS2)', items: [ 'Vollständiges Audit-Log aller Orchestrierungsaktionen — wer hat was wann geändert (Art. 21 (2h))', + 'Zwei-Faktor-Authentifizierung (MFA/TOTP), pro Rolle erzwingbar — Zugangskontrolle für administrative Konten (Art. 21 (2i))', 'RBAC mit vier integrierten Rollen und benutzerdefinierten Berechtigungssätzen — Zugangskontrollnachweis', 'Patch-Status und installierte Paketliste pro Gerät — Patch-Management-Baseline (Art. 21 (2e))', 'Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) verknüpft mit jedem Gerätedatensatz', + 'Git-basierte Konfigurationssnapshot-Historie mit Diff-Viewer und OPNsense-Restore — Backup- & Recovery-Nachweis auf Konfigurationsebene (Art. 21 (2c))', 'Konfigurationsdrift-Tracking: Sollzustand vs. abgefragter Zustand — nicht autorisierte Änderungen erkennen', 'Security-Agent-Abdeckungsbericht: welche Geräte haben Wazuh, Graylog, CrowdSec aktiv', 'SNMP-Gesundheitsmetriken als kontinuierliche Monitoring-Baseline (Art. 21 (2a))', diff --git a/src/pages/Home.tsx b/src/pages/Home.tsx index 1a5a78e..2da6eb8 100644 --- a/src/pages/Home.tsx +++ b/src/pages/Home.tsx @@ -165,6 +165,39 @@ function MockVlans() { ) } +function MockConfigDiff() { + const snapshots = [ + { id: 'a3f9c1', when: '2 min ago', label: 'current' }, + { id: '7e2b04', when: '1 h ago' }, + { id: 'd819e6', when: '6 h ago' }, + ] + return ( +
+
+ Config — fw-001.lan + +
+
+ {snapshots.map((s) => ( + + {s.id} · {s.when} + + ))} +
+
+
7e2b04 → a3f9c1
+
- set firewall.rule_42.destination_port='22'
+
+ set firewall.rule_42.destination_port='2222'
+
commit
+
+
+

Unauthorized change detected — fw-001.lan

+

Configuration changed outside netOrk between the last two polls.

+
+
+ ) +} + function MockCompliance() { const checks = [ { label: 'Asset inventory', detail: '18 / 18 devices tracked', ok: true }, @@ -375,6 +408,15 @@ export default function Home() { +
+ + + +
+

{h.screenshot4.heading}

+

{h.screenshot4.body}

+
+
diff --git a/src/pages/Nis2.tsx b/src/pages/Nis2.tsx index 432b74d..b648ad3 100644 --- a/src/pages/Nis2.tsx +++ b/src/pages/Nis2.tsx @@ -11,25 +11,25 @@ const REQUIREMENTS: Record<'en' | 'de', Requirement[]> = { en: [ { article: 'Art. 21 (2a)', label: 'Risk analysis & information system security policies', coverage: 'partial', netork: 'Config drift detection, SNMP health metrics, and security agent coverage across all devices provide a continuous risk baseline. A formal risk register is out of scope for netOrk.' }, { article: 'Art. 21 (2b)', label: 'Incident handling', coverage: 'partial', netork: 'Wazuh alert history, CrowdSec decisions, and Graylog syslog per device surface incidents at the network layer. A structured incident record with NIS2 Art. 23 reporting timers is on the roadmap.' }, - { article: 'Art. 21 (2c)', label: 'Business continuity, backup management, disaster recovery', coverage: 'roadmap', netork: 'Git-backed configuration snapshots (on roadmap) provide config-level recovery. Backup monitoring for individual devices is not yet implemented.' }, + { article: 'Art. 21 (2c)', label: 'Business continuity, backup management, disaster recovery', coverage: 'partial', netork: 'Every poll captures a configuration snapshot into a local Git repository — full history, a side-by-side diff viewer between any two points in time, and one-click restore for OPNsense. Backup/recovery for full device state beyond configuration is out of scope.' }, { article: 'Art. 21 (2d)', label: 'Supply chain security', coverage: 'partial', netork: 'Vendor, model, firmware, and OS version are tracked per device after every poll. EOL tracking against endoflife.date is on the roadmap to flag unsupported software.' }, { article: 'Art. 21 (2e)', label: 'Vulnerability handling in acquisition, development & maintenance', coverage: 'covered', netork: 'Per-device update status and installed package list tracked on every poll. Wazuh CVE counts by severity (critical / high / medium) linked directly to each device record. CVE cross-reference against NVD/OSV (without Wazuh) is on the roadmap.' }, { article: 'Art. 21 (2f)', label: 'Assessing effectiveness of cybersecurity measures', coverage: 'partial', netork: 'The audit log records all orchestration actions. A per-site compliance dashboard (on roadmap) will aggregate security agent coverage, drift status, and patch metrics into a single view.' }, { article: 'Art. 21 (2g)', label: 'Basic cyber hygiene & cybersecurity training', coverage: 'na', netork: 'Out of scope for a network orchestration platform. Training and hygiene policies are handled at the organizational level.' }, { article: 'Art. 21 (2h)', label: 'Access control, asset management, human resources security', coverage: 'covered', netork: 'Full device inventory maintained automatically via discovery and continuous polling. RBAC with four built-in roles (viewer / operator / engineer / administrator) and custom role combinations. Complete audit log of all orchestration actions.' }, - { article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'roadmap', netork: 'TOTP-based MFA for netOrk user accounts is on the roadmap. Current authentication is JWT-based (username + password).' }, + { article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'covered', netork: 'TOTP-based MFA for netOrk user accounts — authenticator app at login, backup codes for emergencies, session invalidation on TOTP changes, enforceable per role.' }, { article: 'Art. 21 (2j)', label: 'Physical and environmental security', coverage: 'na', netork: 'Out of scope. Physical security of the infrastructure hosting netOrk is an organizational and facility concern.' }, ], de: [ { article: 'Art. 21 (2a)', label: 'Risikoanalyse und Sicherheitsrichtlinien für Informationssysteme', coverage: 'partial', netork: 'Konfigurationsdrift-Erkennung, SNMP-Gesundheitsmetriken und Security-Agent-Abdeckung über alle Geräte liefern eine kontinuierliche Risiko-Baseline. Ein formales Risikoregister liegt außerhalb des Scopes von netOrk.' }, { article: 'Art. 21 (2b)', label: 'Bewältigung von Sicherheitsvorfällen', coverage: 'partial', netork: 'Wazuh-Alert-Historie, CrowdSec-Entscheidungen und Graylog-Syslog pro Gerät decken Vorfälle auf Netzwerkebene auf. Ein strukturierter Incident-Datensatz mit NIS2 Art. 23 Melde-Timern ist auf der Roadmap.' }, - { article: 'Art. 21 (2c)', label: 'Geschäftskontinuität, Backup-Management, Disaster Recovery', coverage: 'roadmap', netork: 'Git-basierte Konfigurationssnapshots (auf der Roadmap) ermöglichen Wiederherstellung auf Konfigurationsebene. Backup-Monitoring für einzelne Geräte ist noch nicht implementiert.' }, + { article: 'Art. 21 (2c)', label: 'Geschäftskontinuität, Backup-Management, Disaster Recovery', coverage: 'partial', netork: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert — vollständige Historie, ein Side-by-Side-Diff-Viewer zwischen beliebigen Zeitpunkten und Ein-Klick-Restore für OPNsense. Backup/Recovery für den vollständigen Gerätezustand über die Konfiguration hinaus liegt außerhalb des Scopes.' }, { article: 'Art. 21 (2d)', label: 'Supply-Chain-Sicherheit', coverage: 'partial', netork: 'Hersteller, Modell, Firmware und OS-Version werden nach jedem Poll pro Gerät erfasst. EOL-Tracking über endoflife.date ist auf der Roadmap, um nicht unterstützte Software zu kennzeichnen.' }, { article: 'Art. 21 (2e)', label: 'Schwachstellenbehandlung bei Erwerb, Entwicklung & Wartung', coverage: 'covered', netork: 'Update-Status und installierte Paketliste pro Gerät werden bei jedem Poll erfasst. Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) direkt mit jedem Gerätedatensatz verknüpft. CVE-Abgleich gegen NVD/OSV (ohne Wazuh) ist auf der Roadmap.' }, { article: 'Art. 21 (2f)', label: 'Beurteilung der Wirksamkeit von Cybersicherheitsmaßnahmen', coverage: 'partial', netork: 'Das Audit-Log erfasst alle Orchestrierungsaktionen. Ein Compliance-Dashboard pro Standort (auf der Roadmap) wird Security-Agent-Abdeckung, Drift-Status und Patch-Metriken in einer Ansicht zusammenfassen.' }, { article: 'Art. 21 (2g)', label: 'Grundlegende Cyberhygiene und Cybersicherheitsschulungen', coverage: 'na', netork: 'Außerhalb des Scopes einer Netzwerk-Orchestrierungsplattform. Schulungen und Hygiene-Richtlinien werden auf Organisationsebene gehandhabt.' }, { article: 'Art. 21 (2h)', label: 'Zugangskontrolle, Asset-Management, Personalsicherheit', coverage: 'covered', netork: 'Vollständiges Geräteinventar automatisch über Discovery und kontinuierliches Polling gepflegt. RBAC mit vier integrierten Rollen (Betrachter / Operator / Ingenieur / Administrator) und benutzerdefinierten Rollenkombinationen. Vollständiges Audit-Log aller Orchestrierungsaktionen.' }, - { article: 'Art. 21 (2i)', label: 'Multi-Faktor-Authentifizierung', coverage: 'roadmap', netork: 'TOTP-basierte MFA für netOrk-Benutzerkonten ist auf der Roadmap. Die aktuelle Authentifizierung ist JWT-basiert (Benutzername + Passwort).' }, + { article: 'Art. 21 (2i)', label: 'Multi-Faktor-Authentifizierung', coverage: 'covered', netork: 'TOTP-basierte MFA für netOrk-Benutzerkonten — Authenticator-App beim Login, Backup-Codes für Notfälle, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar.' }, { article: 'Art. 21 (2j)', label: 'Physische und umgebungsbezogene Sicherheit', coverage: 'na', netork: 'Außerhalb des Scopes. Die physische Sicherheit der Infrastruktur, die netOrk hostet, ist eine organisatorische und gebäudetechnische Angelegenheit.' }, ], } @@ -47,6 +47,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = { 'Wazuh agent status and CVE counts by severity', 'Graylog syslog forwarding status', 'CrowdSec decisions and ban counts', + 'Git-backed configuration snapshot, diffed against the previous one to detect unauthorized changes', ], }, { @@ -54,6 +55,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = { produces: [ 'Audit log entry: user, timestamp, resource, action', 'Before/after values for configuration changes', + 'Acknowledged warnings logged with the accepting user', ], }, { @@ -62,6 +64,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = { 'Topology graph — network segmentation view', 'Subnet browser — IP space coverage', 'VLAN matrix — which devices carry which VLANs', + 'Configuration diff between any two snapshots; one-click restore (OPNsense)', 'Audit log export to PDF / CSV (roadmap)', ], }, @@ -78,6 +81,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = { 'Wazuh-Agent-Status und CVE-Anzahl nach Schweregrad', 'Graylog-Syslog-Weiterleitungsstatus', 'CrowdSec-Entscheidungen und Ban-Anzahl', + 'Git-basierter Konfigurationssnapshot, gegen den vorherigen geprüft, um nicht autorisierte Änderungen zu erkennen', ], }, { @@ -85,6 +89,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = { produces: [ 'Audit-Log-Eintrag: Benutzer, Zeitstempel, Ressource, Aktion', 'Vorher/Nachher-Werte für Konfigurationsänderungen', + 'Bestätigte (acked) Warnungen werden mit dem bestätigenden Benutzer protokolliert', ], }, { @@ -93,6 +98,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = { 'Topologie-Graph — Netzwerksegmentierungs-Ansicht', 'Subnetz-Browser — IP-Raum-Abdeckung', 'VLAN-Matrix — welche Geräte welche VLANs führen', + 'Konfigurations-Diff zwischen zwei beliebigen Snapshots; Ein-Klick-Restore (OPNsense)', 'Audit-Log-Export als PDF / CSV (Roadmap)', ], }, @@ -102,21 +108,17 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = { const COMING: Record<'en' | 'de', ComingItem[]> = { en: [ { title: 'CVE tracking per device', detail: 'Automatic cross-reference of installed packages against NVD / OSV — no Wazuh agent required.' }, - { title: 'Configuration backup & versioning', detail: 'Git-backed config snapshots after every poll. Detect unauthorized changes, compare over time.' }, { title: 'Compliance dashboard', detail: 'Per-site Art. 21 checklist: asset coverage, patch status, agent deployment, drift, syslog, audit activity.' }, { title: 'Audit log export', detail: 'PDF and CSV export filtered by date range, device, user, or action — ready to hand to an auditor.' }, { title: 'Incident workflow', detail: 'Structured incident records with NIS2 Art. 23 reporting timers (24 h / 72 h) and external webhook delivery.' }, { title: 'EOL tracking', detail: 'Flag devices running end-of-life firmware or OS versions via the endoflife.date API.' }, - { title: 'MFA (TOTP)', detail: 'Time-based one-time passwords as a second factor for netOrk user accounts (Art. 21 (2i)).' }, ], de: [ { title: 'CVE-Tracking pro Gerät', detail: 'Automatischer Abgleich installierter Pakete gegen NVD / OSV — kein Wazuh-Agent erforderlich.' }, - { title: 'Konfigurationsbackup & -versionierung', detail: 'Git-basierte Konfigurationssnapshots nach jedem Poll. Nicht autorisierte Änderungen erkennen, über die Zeit vergleichen.' }, { title: 'Compliance-Dashboard', detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Agent-Deployment, Drift, Syslog, Audit-Aktivität.' }, { title: 'Audit-Log-Export', detail: 'PDF- und CSV-Export gefiltert nach Datumsbereich, Gerät, Benutzer oder Aktion — bereit zur Übergabe an einen Prüfer.' }, { title: 'Incident-Workflow', detail: 'Strukturierte Incident-Datensätze mit NIS2 Art. 23 Melde-Timern (24 h / 72 h) und externer Webhook-Zustellung.' }, { title: 'EOL-Tracking', detail: 'Geräte mit End-of-Life-Firmware oder OS-Versionen über die endoflife.date-API kennzeichnen.' }, - { title: 'MFA (TOTP)', detail: 'Zeitbasierte Einmalpasswörter als zweiter Faktor für netOrk-Benutzerkonten (Art. 21 (2i)).' }, ], } diff --git a/src/pages/Roadmap.tsx b/src/pages/Roadmap.tsx index fd80c58..44e8232 100644 --- a/src/pages/Roadmap.tsx +++ b/src/pages/Roadmap.tsx @@ -13,11 +13,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = { detail: 'Cross-reference installed packages and OS versions against NVD / OSV. Surfaces "this device has 3 unpatched CVEs (CVSS ≥ 7)" without leaving netOrk.', nis2: true, }, - { - title: 'Configuration backup & versioning', - detail: 'Git-backed config snapshots on every poll. Detect unauthorized changes between snapshots and provide rollback targets.', - nis2: true, - }, { title: 'Compliance dashboard', detail: 'Per-site Art. 21 checklist: asset coverage, patch status, security agent deployment, config drift, syslog forwarding, audit activity — aggregated into a single view.', @@ -55,11 +50,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = { detail: 'Flag devices running end-of-life software via the endoflife.date API. Covers OPNsense, OpenWRT, Debian, Ubuntu, and more — matched to the OS versions netOrk already polls.', nis2: true, }, - { - title: 'MFA (TOTP) for netOrk login', - detail: 'Time-based one-time passwords as a second factor for netOrk user accounts. Directly covers NIS2 Art. 21 (2i) MFA requirement for administrative access.', - nis2: true, - }, { title: 'mDNS scanner', detail: 'Discover media devices (Apple TV, Chromecast, Sonos) via mDNS/Bonjour without needing a NAPALM driver. Inventory visibility and firewall segmentation suggestions.', @@ -84,11 +74,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = { detail: 'CVE-Abgleich mit installierten Paketen und OS-Versionen über NVD / OSV. Zeigt „Dieses Gerät hat 3 ungepatchte CVEs (CVSS ≥ 7)" direkt in netOrk an.', nis2: true, }, - { - title: 'Konfigurationsbackup & -versionierung', - detail: 'Git-basierte Konfigurationssnapshots bei jedem Poll. Erkennt nicht autorisierte Änderungen zwischen Snapshots und bietet Rollback-Ziele.', - nis2: true, - }, { title: 'Compliance-Dashboard', detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Security-Agent-Deployment, Config-Drift, Syslog-Weiterleitung, Audit-Aktivität — zusammengefasst in einer Ansicht.', @@ -126,11 +111,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = { detail: 'Markiert Geräte mit End-of-Life-Software über die endoflife.date-API. Deckt OPNsense, OpenWRT, Debian, Ubuntu und weitere ab — abgeglichen mit den OS-Versionen, die netOrk bereits abfragt.', nis2: true, }, - { - title: 'MFA (TOTP) für netOrk-Login', - detail: 'Zeitbasierte Einmalpasswörter als zweiter Faktor für netOrk-Benutzerkonten. Deckt direkt NIS2 Art. 21 (2i) MFA-Anforderung für administrativen Zugang ab.', - nis2: true, - }, { title: 'mDNS-Scanner', detail: 'Entdeckt Mediengeräte (Apple TV, Chromecast, Sonos) über mDNS/Bonjour ohne NAPALM-Treiber. Inventarsichtbarkeit und Empfehlungen zur Firewall-Segmentierung.',