ASSOCIATED DRATA CONTROL
This test is part of the Denial of Public SSH control that ensures no public SSH is allowed to virtualized assets.
WHAT TO DO IF A TEST FAILS
If Drata finds one or more security groups that allow public SSH access the test will fail. With a failed test you will receive a list of groups that allow public SSH access.
To remediate a failed test, you will need to adjust the security group configuration to disallow public SSH on the reported groups.
STEPS FOR PASSING
To ensure a validated state when testing for denial of public SSH, please follow the steps listed in the table below. Once the provider steps have been completed, navigate back to Drata and execute the test.
Provider / Technology | Provider Steps |
AWS - Security Groups |
|
GCP - VPC Network | Within GCP, you will need to verify that either no firewalls are set up or that there are not any configured firewall rules that allow public SSH access. |
HELPFUL RESOURCES