5.12 (L1) Ensure 'OpenSSH SSH Server (sshd)' is set to 'Disabled' or 'Not Installed'

Information

SSH protocol based service to provide secure encrypted communications between two untrusted hosts over an insecure network.

The recommended state for this setting is: Disabled or Not Installed

Note: This service is not installed by default. It is supplied with Windows, but it is installed by enabling an optional Windows feature (

OpenSSH Server

).

Hosting an SSH server from a workstation is an increased security risk, as the attack surface of that workstation is then greatly increased.

Note: This security concern applies to

any

SSH server application installed on a workstation, not just the one supplied with Windows.

Solution

To establish the recommended configuration via GP, set the following UI path to: Disabled or ensure the service is not installed.

Computer Configuration\Policies\Windows Settings\Security Settings\System Services\OpenSSH SSH Server

Impact:

The workstation will not be permitted to be a SSH host server.

See Also

https://workbench.cisecurity.org/benchmarks/16515

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: b64a2b14cad4623a0f0de40fd214138465c1cc59489143775403f1c526fdfa73