ISO 27001 / NIST Compliance Dashboard

System: OpenClaw

Generated: 2026-02-14T13:48:28.592362Z

Risk and Status Overview

Violations2
Partial2
Compliant2
Not Assessed0

High/Critical risk findings: 3

Medium risk findings: 3

Controls Map View

Check IDControlISO 27001NISTStatusRisk
privilege_approval_requiredApproval required before elevated accessA.5.15, A.5.18PR.AA-01, PR.AA-05violationhigh
least_privilege_enforcedLeast privilege execution modeA.5.15, A.5.18PR.AA-01, PR.PS-01complianthigh
elevation_timeout_30mElevated session idle timeoutA.8.2, A.8.15PR.AA-03, DE.CM-01partialmedium
audit_logging_privileged_actionsPrivileged action audit loggingA.8.15, A.8.16DE.AE-03, DE.CM-01partialmedium
open_ports_approvedOpen ports baseline approvalA.8.20, A.8.21PR.PS-02, DE.CM-01violationmedium
insecure_ports_remediatedInsecure ports remediatedA.8.20, A.8.21PR.PS-02, PR.DS-02complianthigh

Violation View

Check IDStatusRiskGapEvidence
privilege_approval_requiredviolationhighRuntime policy does not yet demonstrate universal approval enforcement for elevated actions.openclaw.json and doctor outputs were evaluated for approval-first execution controls.
elevation_timeout_30mpartialmediumGlobal mandatory enforcement for all elevated paths is not yet guaranteed by runtime policy.Timeout guard script is installed with preflight drop logic.
audit_logging_privileged_actionspartialmediumNo single correlated privileged action audit timeline is guaranteed.gateway status reports log paths; root_session_guard records transition metadata.
open_ports_approvedviolationmediumBaseline missing or incomplete when unapproved findings exist.port_monitor.py live output evaluated against approved_ports baseline.

Mitigation View

Check IDMitigationOwnerDue Date
privilege_approval_requiredRoute all privileged tasks through guarded_privileged_exec.py and enforce approval prompts for elevated execution.Security Engineering2026-03-15
least_privilege_enforcedFix state dir ownership/permissions and enforce command allowlist/approval defaults.Platform Security2026-03-07
elevation_timeout_30mInvoke guarded_privileged_exec.py for every elevated operation path.Security Engineering2026-03-15
audit_logging_privileged_actionsCreate append-only correlated audit records linking approval, execution, and drop events.SecOps2026-03-22
open_ports_approvedPopulate ~/.openclaw/security/approved_ports.json and remove unnecessary listeners.Infrastructure2026-02-28
insecure_ports_remediatedEnforce baseline checks to block insecure service ports.Network Security2026-04-01