No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

The Secret Reason You’re About to Fail Your IT Audit

by Markku Rossi
January 7, 2019
in Featured, Internal Audit
man holding head in front of large grade F

Turning a Key Vulnerability into a Victory

No matter what an organization’s major market is, it is probably subject to regulatory compliance requirements, such as PCI, SOX, FISMA and HIPAA. Failing to comply with any of these requirements could result in a failed audit, which can incur hefty penalties. This article by Markku Rossi of SSH.COM shares one little-known reason why organizations are vulnerable to failing a compliance audit.

No matter your organization’s major market or sector, whether you are in the Fortune 5000 or want to be, you are subject to regulatory compliance requirements such as PCI, SOX, FISMA, GDPR, HIPAA or similar. Failing to comply with the relevant requirements could result in a failed audit, which can incur hefty penalties or loss of business continuity.

Many compliance risk factors are hidden in the plumbing of your organization’s IT infrastructure. This article reveals one little-known reason why your organization is vulnerable to failing a compliance audit, as well as best practices for ensuring you’re prepared the next time you need to demonstrate compliance.

The Secret Key to Compliance

Secure Shell (SSH) is an unseen workhorse in IT infrastructure. The SSH protocol enables secure encrypted remote access and file transfer. SSH keys are the ubiquitous method used to grant access to critical systems and data for humans and machines. SSH keys grease the wheels of finance and industry. However, SSH keys are the domain of sysadmins and app developers, part of the mundane daily work of maintaining databases and editing code.

Many organizations have no visibility into the use of SSH and their SSH key environments, just assuming compliance until an auditor identifies the issue or exception in their reports. How SSH servers/clients and SSH keys are managed is critical for ensuring adequate governance in all corporate IT environments, and it’s an acute issue for cardholder data environments, for business-critical automated data transfers and in enterprise DevOps and application development.

Key Steps to Avoiding a Failed Audit

Ensure you have a holistic and integrated strategy for Secure Shell governance and managing SSH keys. This is essential to avoid failing an audit and incurring fines.

Ask the Right Questions

Here are the critical questions to ask to ensure you don’t fail an audit due to mismanaged SSH keys.

Is Secure Shell deployed within my networks, in e.g. the cardholder data environment, in application development or other critical systems?

Rest assured it is. Some experts would say that it is impossible to implement secure networked environments without leveraging the Secure Shell protocol.

Which systems have Secure Shell enabled?

Secure Shell is typically enabled on all systems.

How is Secure Shell used in my networks?

Secure Shell is used for any of the following: system administrator access, application administrator access, developer access, device admin access, automated processes, file transfers, remote desktop access, backup and restore, system failover, VPN access and contractor/partner access.

What is our process for tracking SSH keys?

Any person or process in possession of a private SSH user key has access to accounts with the corresponding public key. Tracking and controlling configuration and distribution of these keys is a basic and critical security requirement.

How often are SSH keys rotated, and what is the process for rotating keys?

A policy should be in place and enforced for regular key rotation. Treat keys as you would user accounts.

What restrictions are in place to prevent authorized users from using Secure Shell access for an unauthorized purpose?

This applies to both interactive users and automated processes using Secure Shell. Keys should be created, managed and monitored using a central unified console. Only grant least privileged access – enough for users to do their job and nothing more. SSH servers should be hardened. Keys should be configured with quantum-ready encryption.

What monitoring is in place to record encrypted SSH connections and activities performed during encrypted sessions?

Privileged activities, such as those conducted by systems and applications administrators, third parties and subcontractors, should be monitored, logged and reviewed with full audit trail according to defined security policies and procedures.

What mechanisms or controls are in place to prevent SSH-based access between production and non-production environments?

SSH keys used by developers and testers must not enable access from your development servers to production. Remnant nonproduction access may lead to audit infractions, vulnerabilities and breaches.

Looking Ahead

Risk managers and internal auditors have to pick and choose their battles and decide when to take a proactive or reactive stance. When assessing compliance risk from weak Secure Shell governance, you want to know, “Am I ready if and when an auditor comes knocking at my door?”

From the outside, unfortunately, it is not a question of if you will experience a breach – it’s a question of when.

By taking control of Secure Shell governance and implementing integrated SSH key management controls, internal risk managers and auditors can help the organization with a basket of easy wins. You mitigate the risk from external attacks and insider data theft, minimize human errors with critical systems secured by SSH, expedite future breach investigations, stop compliance failure and deliver on your reporting requirements.

Now that you know the secret, you can turn this into a key victory.

Previous Post

The Expanding Role of Technology Asset Management (TAM) in Corporate Compliance

Next Post

4 Steps to Streamline Data Subject Requests in 2019

Markku Rossi

Markku Rossi

Markku Rossi is CTO of SSH.COM. Markku brings close to 25 years of software engineering and architecture experience to the company, is responsible for R&D and directs the company’s technology strategy. Markku has extensive knowledge and experience with SSH Communications Security products, having served the company from 1998 through 2005 as a Chief Engineer and a major contributor to the SSH software architecture. Prior to rejoining the company in 2015, he co-founded several companies, such as Codento and ShopAdvisor, and served as CTO at Navicore and as Chief Architect at Nokia. He has a Master of Science degree in Computer Science from Aalto University.

Related Posts

GRC News Roundup Cover

GRC News Roundup: Agiloft, Redgate Software MIND, LinkSquares & More

by Corporate Compliance Insights
July 30, 2026

GRC technology is one of the fastest-growing segments in enterprise software, and compliance professions are rapidly evolving. Here’s the latest...

news roundup_062124

Activist Investors Significantly Increase M&A Sale Pushes

by Staff and Wire Reports
July 30, 2026

Massive data security confidence comes with high data security concerns.

us doj building with flag

Once You’ve Decided to Self-Disclose, Here’s How to Do It Right

by Sean M. Farrell and Thomas F. Rybarczyk
July 29, 2026

Deciding to self-disclose is one thing; doing it well is another, and the difference often shapes whether a company earns...

normandy invasion monument

What a D-Day Weather Forecast Teaches About Decision-Making Under Pressure

by Jim DeLoach
July 28, 2026

Two forecasters, two methods and a go or no-go call with thousands of lives at stake, the D-Day story holds...

Next Post
padlock protecting personal information

4 Steps to Streamline Data Subject Requests in 2019

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights