Some times ago I posted about scc tool, here is a short update with some example reports provided. https://dev.to/melezhik/linux-compliance-checks-with-sparrow-plugin-2160
People can use the plugin to check if their Linux configuration files are security compliant
Sparrow is a Raku automation framework



So. Yes. Ssh access should be passwords only, etc. Some common sense. We don’t need standard to that
What are you basing this on?
Definitely not NIST 800-53, PCI-DSS, or ISO 27001; all of which stipulate ssh key management not password-based authentication.