diff --git a/docs/PAGES.md b/docs/PAGES.md
index edce3c1..02e2c9b 100644
--- a/docs/PAGES.md
+++ b/docs/PAGES.md
@@ -147,6 +147,15 @@ Each badge uses the `Driver / Integration Badge` component from DESIGN.md.
agent is missing. Graylog syslog forwarding status with auto-fix.`
- Screenshot: SecurityTab inside DeviceDetailPage
+**Row 4 — Right text, left screenshot**
+- Heading: `Configuration backup and versioning`
+- Copy: `Every poll captures a config snapshot into a local Git
+ repository. The Config tab shows the full snapshot history, a
+ side-by-side diff between any two points in time, and — for
+ OPNsense — a Restore button. Unauthorized changes show up as a
+ device warning.`
+- Screenshot: ConfigTab inside DeviceDetailPage
+
---
### Section 5b — NIS2
@@ -330,7 +339,6 @@ address NIS2 Art. 21 technical baseline requirements.
**Planned items (NIS2-tagged):**
- CVE tracking per device — NVD / OSV cross-reference
-- Configuration backup & versioning — git-backed snapshots, change detection
- Compliance dashboard — per-site Art. 21 checklist view
- Audit log export — PDF / CSV with filters
@@ -342,7 +350,6 @@ address NIS2 Art. 21 technical baseline requirements.
**Under consideration (NIS2-tagged):**
- Incident workflow — structured record + NIS2 Art. 23 Fristen-Tracker
- EOL tracking — endoflife.date integration for firmware / OS
-- MFA (TOTP) — second factor for netOrk logins
**Under consideration (general):**
- mDNS scanner — media device discovery
diff --git a/docs/PRODUCT.md b/docs/PRODUCT.md
index a612fc9..a544385 100644
--- a/docs/PRODUCT.md
+++ b/docs/PRODUCT.md
@@ -68,7 +68,8 @@ hardware and want operational visibility beyond what consumer dashboards offer.
9. **NIS2 evidence foundation** — NIS2 Art. 21 mandates asset inventory, patch
management, access control, and audit trails. netOrk produces all of these as
day-to-day operational outputs: full device inventory, per-device update status,
- Wazuh CVE tracking, RBAC, config drift detection, and a complete audit log.
+ Wazuh CVE tracking, RBAC with MFA, Git-backed config snapshots with diff/restore,
+ config drift detection, and a complete audit log.
---
@@ -120,6 +121,11 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
- One-click drift fix stream with live SSH output in the browser
- UCI-based config push for OpenWRT (VLAN names, SSID settings, radio config)
- AP profile system: country code, HT/VHT mode, 802.11r, NTP, syslog, SSH port
+- Configuration backup & versioning: every poll captures a config snapshot into
+ a local Git repository, with full history and a side-by-side diff viewer
+ between any two points in time
+- One-click config restore for OPNsense from any prior snapshot
+- Unauthorised configuration changes are surfaced as a device warning
### Scheduled Operations
- Scheduled reboots for OpenWRT APs with per-site concurrency lock
@@ -130,6 +136,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
### Monitoring & Health
- SNMP health metrics (CPU, memory, interface counters) via `get_health_metrics()`
- Per-device warning system with severity levels (error / warning / info)
+- One-click Ack on any warning — clears it immediately and writes an audit log
+ entry; for config-change warnings the current state is accepted as the new
+ baseline
- Docker container and image status (Proxmox/Linux)
- Service status and start/stop/restart (systemd)
- VM/container list with OS device cross-linking (Proxmox)
@@ -148,6 +157,9 @@ Plus all built-in NAPALM drivers: Cisco IOS/IOS-XE/NX-OS, Arista EOS, Juniper Ju
### Access Control
- JWT authentication with remember-me (localStorage) or session-only (sessionStorage)
+- Two-factor authentication (MFA/TOTP) — authenticator app at login, backup
+ codes for emergencies, session invalidation on TOTP changes, enforceable
+ per role
- RBAC with four built-in roles: viewer / operator / engineer / administrator
- Custom roles with any permission combination
- Full audit log of all orchestration actions
diff --git a/src/i18n/translations.ts b/src/i18n/translations.ts
index 63bd137..70cf07b 100644
--- a/src/i18n/translations.ts
+++ b/src/i18n/translations.ts
@@ -63,6 +63,10 @@ const en = {
heading: 'Security visibility per device',
body: 'Wazuh agent status, CVE counts by severity, and recent alerts — all linked to the device record. One-click agent install if the agent is missing. Graylog syslog forwarding status with auto-fix.',
},
+ screenshot4: {
+ heading: 'Configuration backup and versioning',
+ body: 'Every poll captures a config snapshot into a local Git repository. The Config tab shows the full snapshot history, a side-by-side diff between any two points in time, and — for OPNsense — a Restore button. Unauthorized changes show up as a device warning.',
+ },
nis2Label: 'NIS2 · Art. 21',
nis2Heading: 'Evidence, not paperwork.',
nis2Body: "NIS2 Art. 21 mandates asset inventory, patch management, access control, and audit trails as baseline technical measures. netOrk doesn't bolt on a compliance layer — these are its day-to-day outputs.",
@@ -141,6 +145,9 @@ const en = {
'One-click drift fix stream with live SSH output in the browser',
'UCI-based config push for OpenWRT (VLAN names, SSID settings, radio config)',
'AP profile system: country code, HT/VHT mode, 802.11r, NTP, syslog, SSH port',
+ 'Configuration backup & versioning: every poll snapshots config into a local Git repo, with full history and a side-by-side diff viewer',
+ 'One-click config restore for OPNsense from any prior snapshot',
+ 'Unauthorized configuration changes are surfaced as a device warning',
],
},
{
@@ -157,6 +164,7 @@ const en = {
items: [
'SNMP health metrics (CPU, memory, interface counters) via get_health_metrics()',
'Per-device warning system with severity levels (error / warning / info)',
+ 'One-click Ack on any warning — clears it immediately and logs the action; config-change warnings accept the current state as the new baseline',
'Docker container and image status (Proxmox/Linux)',
'Service status and start/stop/restart (systemd)',
'VM/container list with OS device cross-linking (Proxmox)',
@@ -183,6 +191,7 @@ const en = {
title: 'Access Control (RBAC)',
items: [
'JWT authentication with remember-me (localStorage) or session-only (sessionStorage)',
+ 'Two-factor authentication (MFA/TOTP): authenticator app at login, backup codes, session invalidation on TOTP changes, enforceable per role',
'RBAC with four built-in roles: viewer / operator / engineer / administrator',
'Custom roles with any permission combination',
'Full audit log of all orchestration actions',
@@ -200,9 +209,11 @@ const en = {
title: 'Compliance & Audit (NIS2)',
items: [
'Full audit log of all orchestration actions — who changed what, when (Art. 21 (2h))',
+ 'Two-factor authentication (MFA/TOTP), enforceable per role — administrative access control (Art. 21 (2i))',
'RBAC with four built-in roles and custom permission sets — access control evidence',
'Per-device patch status and installed package list — patch management baseline (Art. 21 (2e))',
'Wazuh CVE counts by severity (critical / high / medium) linked to each device record',
+ 'Git-backed configuration snapshot history with diff viewer and OPNsense restore — config-level backup & recovery evidence (Art. 21 (2c))',
'Config drift tracking: desired state vs. polled state — detect unauthorized changes',
'Security agent coverage report: which devices have Wazuh, Graylog, CrowdSec active',
'SNMP health metrics as continuous monitoring baseline (Art. 21 (2a))',
@@ -335,6 +346,10 @@ const de: Translations = {
heading: 'Sicherheitssichtbarkeit pro Gerät',
body: 'Wazuh-Agent-Status, CVE-Anzahl nach Schweregrad und aktuelle Alerts — alle mit dem Gerätedatensatz verknüpft. Ein-Klick-Agent-Installation falls der Agent fehlt. Graylog-Syslog-Weiterleitungsstatus mit Auto-Fix.',
},
+ screenshot4: {
+ heading: 'Konfigurationsbackup und -versionierung',
+ body: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert. Der Config-Tab zeigt die vollständige Snapshot-Historie, einen Side-by-Side-Diff zwischen beliebigen Zeitpunkten und — für OPNsense — einen Restore-Button. Nicht autorisierte Änderungen erscheinen als Gerätewarnung.',
+ },
nis2Label: 'NIS2 · Art. 21',
nis2Heading: 'Nachweise, keine Papierwüste.',
nis2Body: 'NIS2 Art. 21 schreibt Geräteinventar, Patch-Management, Zugangskontrolle und Audit-Trails als technische Basismaßnahmen vor. netOrk fügt keine Compliance-Schicht auf — das sind seine normalen Tagesausgaben.',
@@ -413,6 +428,9 @@ const de: Translations = {
'Ein-Klick-Drift-Fix-Stream mit Live-SSH-Output im Browser',
'UCI-basierter Config-Push für OpenWRT (VLAN-Namen, SSID-Einstellungen, Radio-Konfiguration)',
'AP-Profil-System: Ländercode, HT/VHT-Modus, 802.11r, NTP, Syslog, SSH-Port',
+ 'Konfigurationsbackup & -versionierung: bei jedem Poll wird ein Snapshot in ein lokales Git-Repository geschrieben — vollständige Historie und Side-by-Side-Diff-Viewer',
+ 'Ein-Klick-Konfigurations-Restore für OPNsense aus jedem früheren Snapshot',
+ 'Nicht autorisierte Konfigurationsänderungen werden als Gerätewarnung angezeigt',
],
},
{
@@ -429,6 +447,7 @@ const de: Translations = {
items: [
'SNMP-Gesundheitsmetriken (CPU, Speicher, Schnittstellenzähler) via get_health_metrics()',
'Gerätespezifisches Warnsystem mit Schweregraden (Fehler / Warnung / Info)',
+ 'Ein-Klick-Ack für jede Warnung — löscht sie sofort und protokolliert die Aktion; bei Config-Change-Warnungen wird der aktuelle Zustand als neue Baseline akzeptiert',
'Docker-Container- und Image-Status (Proxmox/Linux)',
'Service-Status und Start/Stop/Neustart (systemd)',
'VM/Container-Liste mit OS-Geräteverknüpfung (Proxmox)',
@@ -455,6 +474,7 @@ const de: Translations = {
title: 'Zugangskontrolle (RBAC)',
items: [
'JWT-Authentifizierung mit Remember-Me (localStorage) oder nur Sitzung (sessionStorage)',
+ 'Zwei-Faktor-Authentifizierung (MFA/TOTP): Authenticator-App beim Login, Backup-Codes, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar',
'RBAC mit vier integrierten Rollen: Betrachter / Operator / Ingenieur / Administrator',
'Benutzerdefinierte Rollen mit beliebiger Berechtigungskombination',
'Vollständiges Audit-Log aller Orchestrierungsaktionen',
@@ -472,9 +492,11 @@ const de: Translations = {
title: 'Compliance & Audit (NIS2)',
items: [
'Vollständiges Audit-Log aller Orchestrierungsaktionen — wer hat was wann geändert (Art. 21 (2h))',
+ 'Zwei-Faktor-Authentifizierung (MFA/TOTP), pro Rolle erzwingbar — Zugangskontrolle für administrative Konten (Art. 21 (2i))',
'RBAC mit vier integrierten Rollen und benutzerdefinierten Berechtigungssätzen — Zugangskontrollnachweis',
'Patch-Status und installierte Paketliste pro Gerät — Patch-Management-Baseline (Art. 21 (2e))',
'Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) verknüpft mit jedem Gerätedatensatz',
+ 'Git-basierte Konfigurationssnapshot-Historie mit Diff-Viewer und OPNsense-Restore — Backup- & Recovery-Nachweis auf Konfigurationsebene (Art. 21 (2c))',
'Konfigurationsdrift-Tracking: Sollzustand vs. abgefragter Zustand — nicht autorisierte Änderungen erkennen',
'Security-Agent-Abdeckungsbericht: welche Geräte haben Wazuh, Graylog, CrowdSec aktiv',
'SNMP-Gesundheitsmetriken als kontinuierliche Monitoring-Baseline (Art. 21 (2a))',
diff --git a/src/pages/Home.tsx b/src/pages/Home.tsx
index 1a5a78e..2da6eb8 100644
--- a/src/pages/Home.tsx
+++ b/src/pages/Home.tsx
@@ -165,6 +165,39 @@ function MockVlans() {
)
}
+function MockConfigDiff() {
+ const snapshots = [
+ { id: 'a3f9c1', when: '2 min ago', label: 'current' },
+ { id: '7e2b04', when: '1 h ago' },
+ { id: 'd819e6', when: '6 h ago' },
+ ]
+ return (
+
diff --git a/src/pages/Nis2.tsx b/src/pages/Nis2.tsx
index 432b74d..b648ad3 100644
--- a/src/pages/Nis2.tsx
+++ b/src/pages/Nis2.tsx
@@ -11,25 +11,25 @@ const REQUIREMENTS: Record<'en' | 'de', Requirement[]> = {
en: [
{ article: 'Art. 21 (2a)', label: 'Risk analysis & information system security policies', coverage: 'partial', netork: 'Config drift detection, SNMP health metrics, and security agent coverage across all devices provide a continuous risk baseline. A formal risk register is out of scope for netOrk.' },
{ article: 'Art. 21 (2b)', label: 'Incident handling', coverage: 'partial', netork: 'Wazuh alert history, CrowdSec decisions, and Graylog syslog per device surface incidents at the network layer. A structured incident record with NIS2 Art. 23 reporting timers is on the roadmap.' },
- { article: 'Art. 21 (2c)', label: 'Business continuity, backup management, disaster recovery', coverage: 'roadmap', netork: 'Git-backed configuration snapshots (on roadmap) provide config-level recovery. Backup monitoring for individual devices is not yet implemented.' },
+ { article: 'Art. 21 (2c)', label: 'Business continuity, backup management, disaster recovery', coverage: 'partial', netork: 'Every poll captures a configuration snapshot into a local Git repository — full history, a side-by-side diff viewer between any two points in time, and one-click restore for OPNsense. Backup/recovery for full device state beyond configuration is out of scope.' },
{ article: 'Art. 21 (2d)', label: 'Supply chain security', coverage: 'partial', netork: 'Vendor, model, firmware, and OS version are tracked per device after every poll. EOL tracking against endoflife.date is on the roadmap to flag unsupported software.' },
{ article: 'Art. 21 (2e)', label: 'Vulnerability handling in acquisition, development & maintenance', coverage: 'covered', netork: 'Per-device update status and installed package list tracked on every poll. Wazuh CVE counts by severity (critical / high / medium) linked directly to each device record. CVE cross-reference against NVD/OSV (without Wazuh) is on the roadmap.' },
{ article: 'Art. 21 (2f)', label: 'Assessing effectiveness of cybersecurity measures', coverage: 'partial', netork: 'The audit log records all orchestration actions. A per-site compliance dashboard (on roadmap) will aggregate security agent coverage, drift status, and patch metrics into a single view.' },
{ article: 'Art. 21 (2g)', label: 'Basic cyber hygiene & cybersecurity training', coverage: 'na', netork: 'Out of scope for a network orchestration platform. Training and hygiene policies are handled at the organizational level.' },
{ article: 'Art. 21 (2h)', label: 'Access control, asset management, human resources security', coverage: 'covered', netork: 'Full device inventory maintained automatically via discovery and continuous polling. RBAC with four built-in roles (viewer / operator / engineer / administrator) and custom role combinations. Complete audit log of all orchestration actions.' },
- { article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'roadmap', netork: 'TOTP-based MFA for netOrk user accounts is on the roadmap. Current authentication is JWT-based (username + password).' },
+ { article: 'Art. 21 (2i)', label: 'Multi-factor authentication', coverage: 'covered', netork: 'TOTP-based MFA for netOrk user accounts — authenticator app at login, backup codes for emergencies, session invalidation on TOTP changes, enforceable per role.' },
{ article: 'Art. 21 (2j)', label: 'Physical and environmental security', coverage: 'na', netork: 'Out of scope. Physical security of the infrastructure hosting netOrk is an organizational and facility concern.' },
],
de: [
{ article: 'Art. 21 (2a)', label: 'Risikoanalyse und Sicherheitsrichtlinien für Informationssysteme', coverage: 'partial', netork: 'Konfigurationsdrift-Erkennung, SNMP-Gesundheitsmetriken und Security-Agent-Abdeckung über alle Geräte liefern eine kontinuierliche Risiko-Baseline. Ein formales Risikoregister liegt außerhalb des Scopes von netOrk.' },
{ article: 'Art. 21 (2b)', label: 'Bewältigung von Sicherheitsvorfällen', coverage: 'partial', netork: 'Wazuh-Alert-Historie, CrowdSec-Entscheidungen und Graylog-Syslog pro Gerät decken Vorfälle auf Netzwerkebene auf. Ein strukturierter Incident-Datensatz mit NIS2 Art. 23 Melde-Timern ist auf der Roadmap.' },
- { article: 'Art. 21 (2c)', label: 'Geschäftskontinuität, Backup-Management, Disaster Recovery', coverage: 'roadmap', netork: 'Git-basierte Konfigurationssnapshots (auf der Roadmap) ermöglichen Wiederherstellung auf Konfigurationsebene. Backup-Monitoring für einzelne Geräte ist noch nicht implementiert.' },
+ { article: 'Art. 21 (2c)', label: 'Geschäftskontinuität, Backup-Management, Disaster Recovery', coverage: 'partial', netork: 'Bei jedem Poll wird ein Konfigurationssnapshot in einem lokalen Git-Repository gespeichert — vollständige Historie, ein Side-by-Side-Diff-Viewer zwischen beliebigen Zeitpunkten und Ein-Klick-Restore für OPNsense. Backup/Recovery für den vollständigen Gerätezustand über die Konfiguration hinaus liegt außerhalb des Scopes.' },
{ article: 'Art. 21 (2d)', label: 'Supply-Chain-Sicherheit', coverage: 'partial', netork: 'Hersteller, Modell, Firmware und OS-Version werden nach jedem Poll pro Gerät erfasst. EOL-Tracking über endoflife.date ist auf der Roadmap, um nicht unterstützte Software zu kennzeichnen.' },
{ article: 'Art. 21 (2e)', label: 'Schwachstellenbehandlung bei Erwerb, Entwicklung & Wartung', coverage: 'covered', netork: 'Update-Status und installierte Paketliste pro Gerät werden bei jedem Poll erfasst. Wazuh-CVE-Anzahl nach Schweregrad (kritisch / hoch / mittel) direkt mit jedem Gerätedatensatz verknüpft. CVE-Abgleich gegen NVD/OSV (ohne Wazuh) ist auf der Roadmap.' },
{ article: 'Art. 21 (2f)', label: 'Beurteilung der Wirksamkeit von Cybersicherheitsmaßnahmen', coverage: 'partial', netork: 'Das Audit-Log erfasst alle Orchestrierungsaktionen. Ein Compliance-Dashboard pro Standort (auf der Roadmap) wird Security-Agent-Abdeckung, Drift-Status und Patch-Metriken in einer Ansicht zusammenfassen.' },
{ article: 'Art. 21 (2g)', label: 'Grundlegende Cyberhygiene und Cybersicherheitsschulungen', coverage: 'na', netork: 'Außerhalb des Scopes einer Netzwerk-Orchestrierungsplattform. Schulungen und Hygiene-Richtlinien werden auf Organisationsebene gehandhabt.' },
{ article: 'Art. 21 (2h)', label: 'Zugangskontrolle, Asset-Management, Personalsicherheit', coverage: 'covered', netork: 'Vollständiges Geräteinventar automatisch über Discovery und kontinuierliches Polling gepflegt. RBAC mit vier integrierten Rollen (Betrachter / Operator / Ingenieur / Administrator) und benutzerdefinierten Rollenkombinationen. Vollständiges Audit-Log aller Orchestrierungsaktionen.' },
- { article: 'Art. 21 (2i)', label: 'Multi-Faktor-Authentifizierung', coverage: 'roadmap', netork: 'TOTP-basierte MFA für netOrk-Benutzerkonten ist auf der Roadmap. Die aktuelle Authentifizierung ist JWT-basiert (Benutzername + Passwort).' },
+ { article: 'Art. 21 (2i)', label: 'Multi-Faktor-Authentifizierung', coverage: 'covered', netork: 'TOTP-basierte MFA für netOrk-Benutzerkonten — Authenticator-App beim Login, Backup-Codes für Notfälle, Session-Invalidierung bei TOTP-Änderungen, pro Rolle erzwingbar.' },
{ article: 'Art. 21 (2j)', label: 'Physische und umgebungsbezogene Sicherheit', coverage: 'na', netork: 'Außerhalb des Scopes. Die physische Sicherheit der Infrastruktur, die netOrk hostet, ist eine organisatorische und gebäudetechnische Angelegenheit.' },
],
}
@@ -47,6 +47,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
'Wazuh agent status and CVE counts by severity',
'Graylog syslog forwarding status',
'CrowdSec decisions and ban counts',
+ 'Git-backed configuration snapshot, diffed against the previous one to detect unauthorized changes',
],
},
{
@@ -54,6 +55,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
produces: [
'Audit log entry: user, timestamp, resource, action',
'Before/after values for configuration changes',
+ 'Acknowledged warnings logged with the accepting user',
],
},
{
@@ -62,6 +64,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
'Topology graph — network segmentation view',
'Subnet browser — IP space coverage',
'VLAN matrix — which devices carry which VLANs',
+ 'Configuration diff between any two snapshots; one-click restore (OPNsense)',
'Audit log export to PDF / CSV (roadmap)',
],
},
@@ -78,6 +81,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
'Wazuh-Agent-Status und CVE-Anzahl nach Schweregrad',
'Graylog-Syslog-Weiterleitungsstatus',
'CrowdSec-Entscheidungen und Ban-Anzahl',
+ 'Git-basierter Konfigurationssnapshot, gegen den vorherigen geprüft, um nicht autorisierte Änderungen zu erkennen',
],
},
{
@@ -85,6 +89,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
produces: [
'Audit-Log-Eintrag: Benutzer, Zeitstempel, Ressource, Aktion',
'Vorher/Nachher-Werte für Konfigurationsänderungen',
+ 'Bestätigte (acked) Warnungen werden mit dem bestätigenden Benutzer protokolliert',
],
},
{
@@ -93,6 +98,7 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
'Topologie-Graph — Netzwerksegmentierungs-Ansicht',
'Subnetz-Browser — IP-Raum-Abdeckung',
'VLAN-Matrix — welche Geräte welche VLANs führen',
+ 'Konfigurations-Diff zwischen zwei beliebigen Snapshots; Ein-Klick-Restore (OPNsense)',
'Audit-Log-Export als PDF / CSV (Roadmap)',
],
},
@@ -102,21 +108,17 @@ const EVIDENCE: Record<'en' | 'de', EvidenceBlock[]> = {
const COMING: Record<'en' | 'de', ComingItem[]> = {
en: [
{ title: 'CVE tracking per device', detail: 'Automatic cross-reference of installed packages against NVD / OSV — no Wazuh agent required.' },
- { title: 'Configuration backup & versioning', detail: 'Git-backed config snapshots after every poll. Detect unauthorized changes, compare over time.' },
{ title: 'Compliance dashboard', detail: 'Per-site Art. 21 checklist: asset coverage, patch status, agent deployment, drift, syslog, audit activity.' },
{ title: 'Audit log export', detail: 'PDF and CSV export filtered by date range, device, user, or action — ready to hand to an auditor.' },
{ title: 'Incident workflow', detail: 'Structured incident records with NIS2 Art. 23 reporting timers (24 h / 72 h) and external webhook delivery.' },
{ title: 'EOL tracking', detail: 'Flag devices running end-of-life firmware or OS versions via the endoflife.date API.' },
- { title: 'MFA (TOTP)', detail: 'Time-based one-time passwords as a second factor for netOrk user accounts (Art. 21 (2i)).' },
],
de: [
{ title: 'CVE-Tracking pro Gerät', detail: 'Automatischer Abgleich installierter Pakete gegen NVD / OSV — kein Wazuh-Agent erforderlich.' },
- { title: 'Konfigurationsbackup & -versionierung', detail: 'Git-basierte Konfigurationssnapshots nach jedem Poll. Nicht autorisierte Änderungen erkennen, über die Zeit vergleichen.' },
{ title: 'Compliance-Dashboard', detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Agent-Deployment, Drift, Syslog, Audit-Aktivität.' },
{ title: 'Audit-Log-Export', detail: 'PDF- und CSV-Export gefiltert nach Datumsbereich, Gerät, Benutzer oder Aktion — bereit zur Übergabe an einen Prüfer.' },
{ title: 'Incident-Workflow', detail: 'Strukturierte Incident-Datensätze mit NIS2 Art. 23 Melde-Timern (24 h / 72 h) und externer Webhook-Zustellung.' },
{ title: 'EOL-Tracking', detail: 'Geräte mit End-of-Life-Firmware oder OS-Versionen über die endoflife.date-API kennzeichnen.' },
- { title: 'MFA (TOTP)', detail: 'Zeitbasierte Einmalpasswörter als zweiter Faktor für netOrk-Benutzerkonten (Art. 21 (2i)).' },
],
}
diff --git a/src/pages/Roadmap.tsx b/src/pages/Roadmap.tsx
index fd80c58..44e8232 100644
--- a/src/pages/Roadmap.tsx
+++ b/src/pages/Roadmap.tsx
@@ -13,11 +13,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
detail: 'Cross-reference installed packages and OS versions against NVD / OSV. Surfaces "this device has 3 unpatched CVEs (CVSS ≥ 7)" without leaving netOrk.',
nis2: true,
},
- {
- title: 'Configuration backup & versioning',
- detail: 'Git-backed config snapshots on every poll. Detect unauthorized changes between snapshots and provide rollback targets.',
- nis2: true,
- },
{
title: 'Compliance dashboard',
detail: 'Per-site Art. 21 checklist: asset coverage, patch status, security agent deployment, config drift, syslog forwarding, audit activity — aggregated into a single view.',
@@ -55,11 +50,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
detail: 'Flag devices running end-of-life software via the endoflife.date API. Covers OPNsense, OpenWRT, Debian, Ubuntu, and more — matched to the OS versions netOrk already polls.',
nis2: true,
},
- {
- title: 'MFA (TOTP) for netOrk login',
- detail: 'Time-based one-time passwords as a second factor for netOrk user accounts. Directly covers NIS2 Art. 21 (2i) MFA requirement for administrative access.',
- nis2: true,
- },
{
title: 'mDNS scanner',
detail: 'Discover media devices (Apple TV, Chromecast, Sonos) via mDNS/Bonjour without needing a NAPALM driver. Inventory visibility and firewall segmentation suggestions.',
@@ -84,11 +74,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
detail: 'CVE-Abgleich mit installierten Paketen und OS-Versionen über NVD / OSV. Zeigt „Dieses Gerät hat 3 ungepatchte CVEs (CVSS ≥ 7)" direkt in netOrk an.',
nis2: true,
},
- {
- title: 'Konfigurationsbackup & -versionierung',
- detail: 'Git-basierte Konfigurationssnapshots bei jedem Poll. Erkennt nicht autorisierte Änderungen zwischen Snapshots und bietet Rollback-Ziele.',
- nis2: true,
- },
{
title: 'Compliance-Dashboard',
detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Security-Agent-Deployment, Config-Drift, Syslog-Weiterleitung, Audit-Aktivität — zusammengefasst in einer Ansicht.',
@@ -126,11 +111,6 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
detail: 'Markiert Geräte mit End-of-Life-Software über die endoflife.date-API. Deckt OPNsense, OpenWRT, Debian, Ubuntu und weitere ab — abgeglichen mit den OS-Versionen, die netOrk bereits abfragt.',
nis2: true,
},
- {
- title: 'MFA (TOTP) für netOrk-Login',
- detail: 'Zeitbasierte Einmalpasswörter als zweiter Faktor für netOrk-Benutzerkonten. Deckt direkt NIS2 Art. 21 (2i) MFA-Anforderung für administrativen Zugang ab.',
- nis2: true,
- },
{
title: 'mDNS-Scanner',
detail: 'Entdeckt Mediengeräte (Apple TV, Chromecast, Sonos) über mDNS/Bonjour ohne NAPALM-Treiber. Inventarsichtbarkeit und Empfehlungen zur Firewall-Segmentierung.',