SSH
What is SSH?
Secure Shell, a cryptographic network protocol for secure remote login, command execution, and file transfer between computers over unsecured networks.
Terms that appear alongside ssh
Each of these is named in at least one of the same controls as ssh. The number is how many controls name both.
- authentication 7 shared controls
- tls 6 shared controls
- nist 5 shared controls
- ipsec 5 shared controls
- remote access 4 shared controls
- firewall 3 shared controls
- pki 3 shared controls
- audit 2 shared controls
Frameworks that govern ssh
What the standards actually require on ssh
Requirements naming ssh across 6 standards, quoted from the control text.
If using remote access without the use of a password for SSH connections, the 'forced command' option is used to specify what command is executed and parameter checking is enabled.
ISM-0488 · If using remote access without the use of a password for SSH connections, the 'forced comm →Implement cryptography + protocol security + PKI per O-RAN WG11 Security Requirements covering TLS + SSH + IPsec + certificate lifecycle.
ORANWG11-3 · Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management →Securely manage network infrastructure. Example implementations include version-controlled-infrastructure-as-code, and the use of secure network protocols, such as SSH and HTTPS.
CIS-12.3 · Securely Manage Network Infrastructure →Security Dimensions 4 and 5 per X.805 Clauses 6.4 and 6.5 are closely related: (1) Data Confidentiality (Dim 4) protects data from unauthorized disclosure - ensures that the data content cannot be understood by unauthorized entities.
X805-Dim4-5-Data-Confidentiality-Communication-Security-Encryption-Information-Flow-Protection · ITU-T X.805 Security Dimensions 4-5 - Data Confidentiality + Communication Security + Encryption At-Rest + In-Transit + In-Use + Information Flow Protection + Steered Communication + Anti-Tap + Anti-Eavesdrop + Post-Quantum Cryptography →Deploy FIPS 140-3 validated cryptographic modules (NIST CMVP) supporting ML-KEM + ML-DSA + SLH-DSA. Test against NIST CAVP (Cryptographic Algorithm Validation Program) test vectors.
PQC-7 · FIPS Validated Modules, HSM Readiness, and Algorithm Validation →Apply Section 5.3 cryptography including: encryption of data at rest (AES-256 + FIPS 140-3 validated modules + full disk encryption + file-level encryption + database encryption) + data in transit (TLS 1.3 + IPsec + SSH 2.0 + S/MIME + PGP) + key management per...
NISTSP123-4 · Server Cryptography - Encryption, Key Management, Certificates →Questions people ask about ssh
What is SSH?
Why is SSH important for compliance?
Which compliance frameworks address SSH?
Where can I learn more about SSH?
See how SSH applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.