this post was submitted on 09 Jul 2026
17 points (90.5% liked)
Linux
14906 readers
408 users here now
A community for everything relating to the GNU/Linux operating system (except the memes!)
Also, check out:
Original icon base courtesy of lewing@isc.tamu.edu and The GIMP
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Compliant with what?
"Security compliant" is a completely meaningless phrase, right up there with "locked door" or "secret code".
Whoever downvoted you probably doesn’t understand what you’re saying. This package doesn’t stipulate as to what regulations, frameworks, standards etc it is checking compliance against.
If it doesn’t say what it’s checking it’s compliant against, how can it determine if you’re compliant to it or not?
ISO 27001? SOC2? CIS Benchmarks? HIPAA? GDPR? NIST CSF? 800-53? PCI DSS? Cyber Essentials? Vendor guidance?
This seems, at best, some general security checks but not mapped to any framework in particular.
The Linux Security Audit Project is far more mature in this regard and maps checks to specific frameworks.
So. Yes. Ssh access should be passwords only, etc. Some common sense. We don’t need standard to that
UPDATE: sorry for the typo, meant passwordless
What are you basing this on?
Definitely not NIST 800-53, PCI-DSS, or ISO 27001; all of which stipulate ssh key management not password-based authentication.
Typo )) sorry , meant password less