When you grant users access to connect to virtual machine (VM) instances using
SSH, you impact the security of your VM and any resources that your VM has
access to, such as storage buckets or databases.

You can limit the risks related to SSH access by following several best practices,
including:

- [Control network access](https://docs.cloud.google.com/compute/docs/connect/ssh-best-practices/network-access):
  Implement zero trust access controls to restrict the networks, locations, and
  devices from which users can establish SSH connections to your VMs,
  and avoid VMs from being more exposed than necessary.

- [Control SSH login access](https://docs.cloud.google.com/compute/docs/connect/ssh-best-practices/login-access):
  Restrict which users are allowed to establish SSH sessions and ensure that login
  access is revoked in a timely manner.

- [Protect SSH credentials](https://docs.cloud.google.com/compute/docs/connect/ssh-best-practices/credentials):
  Require users to authenticate with multiple factors and protect credentials from
  being leaked.

- [Audit SSH access](https://docs.cloud.google.com/compute/docs/connect/ssh-best-practices/auditing): Maintain a
  reliable audit trail that tracks all SSH access.

- [Use post-quantum SSH](https://docs.cloud.google.com/compute/docs/connect/ssh-best-practices/post-quantum-ssh):
  Configure post-quantum key exchange algorithms on your clients and VMs to
  protect connections against capture-now, decrypt-later attacks.

## What's next

- Learn more about the [best practices for controlling SSH network access](https://docs.cloud.google.com/compute/docs/connect/ssh-best-practices/network-access)
- Learn more about the [best practices for using post-quantum SSH](https://docs.cloud.google.com/compute/docs/connect/ssh-best-practices/post-quantum-ssh)