CIS Hardened Images FAQ

CIS offers hardened images via several of the major cloud computing vendors. CIS Hardened Images are securely configured according to applicable CIS Benchmarks.

What are CIS Hardened Images?

CIS Hardened Images are virtual machine images which have been configured to secure standards, based upon CIS Benchmarks that are collaboratively developed and used by thousands worldwide.

Where are CIS Hardened Images offered?

CIS Hardened Images are now available through Amazon Web Services (AWS Marketplace, AWS GovCloud, and AWS IC), Google Cloud Platform (GCP) and Microsoft Azure (Azure Marketplace and Azure Government Marketplace).

How are CIS Hardened Images created?

Each CIS Hardened Image is configured to follow the recommendations outlined in its corresponding Benchmark. CIS-CAT Pro Assessor is run to ensure that all appropriate settings are applied for proper conformance to that Benchmark.

Each CIS Hardened Image contains the final CIS-CAT Pro Assessor report to illustrate the hardened image’s compliance with the Benchmark. The report will also be accompanied by a README text file that includes any exceptions necessary for that hardened image to run in the cloud. If any setting in the CIS-CAT Pro Assessor report is identified as “Fail”, there will be an explanation in the exceptions file providing justification as to why that is.

Please note, CIS Hardened Images are configured using local group policy. If your intention is to use these images in a domain environment where policies are managed globally, the majority of our security settings will be changed and managed by your domain policies.

What is the difference between using CIS Hardened Images and utilizing a base image on a cloud platform and applying the corresponding Benchmark?

From a technical perspective, you could utilize a base image and use our CIS Remediation Kits to harden that base image. The most notable differences are in the overall time and resource allocation of your organization to persist in that effort. Additionally, CIS offers expertise in hardening each image with due care while including the necessary exceptions for that image to run correctly relative to each respective cloud platform.

How are the CIS Hardened Images accessed?

CIS Hardened Images are accessed according to the cloud platforms through which they are available. Each platform provides their own instructions associated with accessing their solutions. Please follow the cloud platform specific guidelines to ensure proper connectivity.

How often are CIS Hardened Images updated?

CIS Hardened Images for Microsoft Windows are updated each month in alignment with the Microsoft patch schedule. A new hardened image will be released with a new versioning number to indicate the update completion.

CIS Hardened Images for Linux are updated every 3 to 6 months dependent upon the incorporation of new operating system patches that deem applicable.

New CIS Hardened Images (regardless of their OS) will be developed and made available on each platform any time there is a major or minor update to the corresponding CIS Benchmark itself.

How are new versions and updates visually represented for each CIS Hardened Image?

Each CIS Hardened Image is accompanied by its version number. The version number is
representative of updates made or new releases of a particular image. Below is an example of the CIS Hardened Image versioning.

What steps should be taken when CIS Hardened Images are updated?

Following an update, two options are available in order to ensure compliance with the secure configurations.

1. Migrate to the newest version
2. Reference the corresponding Benchmark and apply the new security settings manually that are located in the change log

In the AWS Marketplace, how do I know I am using the most up to-date CIS Hardened Image?

CIS Hardened Images help you save time and money on hardware purchasing, software licensing, and maintenance. CIS has now made it easy for you to verify that you are using the latest released Amazon Machine Image (AMI) for a particular CIS Benchmark.

Python script for CIS AMIs

In the AWS Marketplace, are CIS Hardened Images available in all instance types?

If a particular instance type is applicable to the version of the OS that is running on the hardened image, it should be available. If you are in search of a specific instance type and do not see that offering available, please email support@cisecurity.org.