Bastion Host
What is Bastion Host?
A specially hardened computer on a network designed to withstand attacks and serve as a single point of entry to internal resources. Bastion hosts are typically placed in a DMZ and run minimal services.
Terms that appear alongside bastion host
Each of these is named in at least one of the same controls as bastion host. The number is how many controls name both.
- remote access 2 shared controls
- nist 2 shared controls
- jump server 2 shared controls
- access control 2 shared controls
Frameworks that govern bastion host
What the standards actually require on bastion host
Requirements naming bastion host across 6 standards, quoted from the control text.
ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...
ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC →Implement NIST 800-53 AC Access Control family + IA Identification and Authentication family per MARS-E v2.0 catalog. NIST 800-63-3 Identity Assurance Level 2 (IAL2) + Authenticator Assurance Level 2 (AAL2) + Federation Assurance Level 2 (FAL2) for Exchange co...
MARS-E-Access-Control-Identity-Authentication-NIST-800-63-Identity-Assurance-Levels-MFA-AC-IA-Families · MARS-E Access Control + Identity + Authentication + NIST 800-63 + MFA + AC + IA Families →Implement Operations Security + Physical/Environmental Security + Communications and Network Security per MTCS SS 584. Operations Security (ISO 27001 Annex A.12 alignment) - documented operating procedures + capacity management + separation of dev/test/prod +...
MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS · MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS →Implement Access Control + Cryptography + Network and Infrastructure Security per MAS TRM Chapters 9 + 10. Chapter 9 Access Control + Cryptography - access control policy + user identification + authentication (Multi-Factor Authentication MFA required for priv...
MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation · MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation →Apply Section 6.3 network security including: network segmentation per NIST SP 800-207 Zero Trust + microsegmentation + DMZ + jump servers + bastion hosts + perimeter firewalls + host-based firewalls + IDS/IPS + DDoS protection + DNS security (DNSSEC + DoH) +...
NISTSP123-6 · Network Security and Server Communications →Apply Section 7.3 identity and access in cloud including: federated identity (SAML 2.0 + OAuth 2.0 + OIDC + WS-Federation) with IdP (Azure AD + Okta + Auth0 + Ping + ForgeRock + AWS IAM Identity Center) + MFA (FIDO2 + WebAuthn + TOTP + biometric) + Single Sign...
NISTSP144-5 · Identity and Access in Cloud, Federation, and Privileged Access →Questions people ask about bastion host
What is Bastion Host?
Why is Bastion Host important for compliance?
Which compliance frameworks address Bastion Host?
Where can I learn more about Bastion Host?
See how Bastion Host applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.