Skip to content
arrow_back
search
ISM-1506 policy ASD Information Security Manual (ISM)

Disable SSH Version 1 for Security

SSH version 1 is turned off to improve security for SSH connections.

record_voice_over

Plain language

This control means switching off the older version of a tool called SSH that lets people connect securely to computers over the internet. It matters because the older version has security holes that can let attackers in, which could mean someone could steal information or take control of your systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The use of SSH version 1 is disabled for SSH connections.
policy ASD Information Security Manual (ISM) ISM-1506
priority_high

Why it matters

Enabling SSH version 1 exposes systems to man-in-the-middle attacks, risking interception or modification of sensitive data in transit.

settings

Operational notes

Configure SSHD to allow only protocol 2. Regularly audit sshd_config and run automated checks to detect SSH v1 being enabled.

Mapping detail

Mapping

Direction

Controls