Documentation
README
Ensure Images are not Publicly Available
Description
EC2 allows you to make an AMI public, sharing it with all AWS accounts.
Rationale
Publicly sharing an AMI with all AWS accounts could expose organizational data and configuration information.
Impact
Making an AMI private may affect other AWS accounts that depend on it. Ensure shared accounts are explicitly added if needed.
Audit Procedure
Using AWS CLI
No specific CLI audit command is provided for this control. Use the console method below.
Using AWS Console
- Login to the EC2 console at https://console.aws.amazon.com/ec2/.
- In the left pane, under
Images, clickAMIs. - Confirm the
Owned by meis set. - Select the AMI from the list.
- Click on the
PermissionsTab. - If this reads
This image is currently Public, please refer to the remediation below.
Expected Result
All AMIs should have their permissions set to Private. No AMI should display "This image is currently Public" in the Permissions tab.
Remediation
Using AWS CLI
No specific CLI remediation command is provided for this control. Use the console method below.
Using AWS Console
- Login to the EC2 console at https://console.aws.amazon.com/ec2/.
- In the left pane, under
Images, clickAMIs. - Confirm the
Owned by meis set. - Select the AMI from the list.
- Click on the
PermissionsTab. - Click on
Edit. - Click on the radio button
Private.
Add AWS Account Number if you have a need to share with other Internal AWS accounts that your Organization owns.
Default Value
By default, AMIs are private when created. They must be explicitly made public.
References
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 11.3 Protect Recovery Data | x | x | x |
| v7 | 5.3 Securely Store Master Images | x | x |
Profile
Level 1 | Manual