Creating Custom AMIs

Information

You can create your own AMIs that meet the specific requirements of your organization and publish them for internal(private) or external (public) use. As a publisher of an AMI, you are responsible for the initial security posture of the machine images that you use in production.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Before you publish an AMI, make sure that the published software is up to date with relevant security patches and perform clean-up and hardening tasks.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7

Plugin: amazon_aws

Control ID: 9e0b3347a6ecafeae3a6c130e5d4fe85c406a10eb985e93ce9fc616042ca531f