SSH access controls relevant to ISO 27001 programmes

Make SSH access easier to control and demonstrate

Reduce reliance on persistent user keys on managed servers through short-lived certificates and centralized permissions, supporting common access-control evidence needs in a wider ISO 27001 programme.

The ISO 27001 challenge

A policy says who should have access. Reviews may also need current operational records.

Infrastructure access often sits outside the clean processes used for business applications. Public keys remain on servers, permissions are reviewed machine by machine, and offboarding depends on someone finding every credential in time.

That can create a gap between the organisation's access-control policy and its operational reality. Depending on the organisation's controls and audit scope, teams may need to reconstruct who was eligible for access, why, and whether eligibility was removed when no longer required.

Unknown access

Long-lived keys make it difficult to produce a current, reliable list of people who can reach each server.

Fragile offboarding

Removing a user from the identity provider does not remove copies of their SSH key from every machine.

Manual evidence

Screenshots, spreadsheets, and server-by-server checks consume time and become outdated quickly.

What Flotte changes

Turn SSH access from permanent credentials into a managed process

Flotte is designed to connect certificate eligibility to a company identity and a central permission decision. Instead of distributing persistent user keys, it can issue a short-lived certificate after its configured identity and permission checks succeed.

01

Replace persistent keys

Short-lived certificates reduce the inventory of credentials that must be discovered, rotated, and removed from servers.

02

Centralize authorization

User-to-server permissions provide one place to understand and change who is intended to access managed infrastructure.

03

Retain useful records

Identity-linked permission and certificate-issuance records can support reviews without rebuilding the complete story from every server.

Why it is valuable

Less credential administration. Better answers when they matter.

For security teams: clearer ownership, shorter credential-validity windows, and a more consistent access-control process.

For infrastructure teams: fewer key-rotation projects and less server-by-server permission cleanup.

For management: a current view of access to managed infrastructure instead of an outdated spreadsheet.

For audits: operational records that may be useful for access reviews and control testing, subject to the audit scope and auditor judgement.

ISO 27001 Programme Context

Capabilities that may support access-control processes

Flotte may help reduce reliance on persistent user keys, centralize access decisions, and retain operational records. Relevance depends on the organisation's risk treatment, control design, scope, and independent assessment.

Access Control

Short-lived certificate authentication and central authorization are designed to reduce reliance on stale user keys and shared credentials.

Operations Security

Identity-linked records for Flotte-managed activity can support access reviews, control testing, and investigations.

Cryptography

SSH certificates are designed to be signed by your own CA and to expire after a configurable, short lifetime.

Incident Management

Removing eligibility centrally is designed to stop future certificate issuance; issued certificates remain valid until expiry.

Control Evidence

Central permissions and operational records can contribute evidence to a wider compliance and assurance programme.

System Security

Certificate authentication works with native OpenSSH without requiring a continuously running Flotte agent on managed servers.

Why certificates over SSH keys?

Persistent user keys can be difficult to inventory, rotate, and remove consistently across servers. Flotte is designed to issue short-lived certificates on demand, centralize permission decisions, and retain records of managed activity. This can reduce manual credential administration, but it does not replace organisational controls, server-side monitoring, access reviews, or independent audit work.

Configurable

Certificate lifetime

Central

Managed records

Reduced

Persistent user keys

Central

Future eligibility

Coming Soon

Build a clearer SSH access-control process

Centralize server permissions, reduce reliance on open-ended credentials, and retain useful access records for your wider information-security programme.