---
name: "CIS AWS Compute 2.1.5: Private AMIs"
slug: cis-aws-compute-2-1-5
category: DevOps
description: Audit and enforce that Amazon Machine Images (AMIs) are not publicly shared to prevent exposure of organizational data and configurations.
github: "https://github.com/CyberStrikeus/CyberStrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Cloud_Providers/AWS/CIS_AWS_Compute_Services_Benchmark_v1.1.0/cis-aws-compute-2.1.5"
language: TypeScript
stars: 1307
forks: 213
install: "git clone https://github.com/CyberStrikeus/CyberStrike"
added: 2026-07-20T06:48:57.786Z
last_synced: 2026-07-29T06:37:10.846Z
canonical_url: "https://dirskills.com/skills/cis-aws-compute-2-1-5"
---

# CIS AWS Compute 2.1.5: Private AMIs

Audit and enforce that Amazon Machine Images (AMIs) are not publicly shared to prevent exposure of organizational data and configurations.

**Install:** `git clone https://github.com/CyberStrikeus/CyberStrike`

## README

# Ensure Images are not Publicly Available

## Description

EC2 allows you to make an AMI public, sharing it with all AWS accounts.

## Rationale

Publicly sharing an AMI with all AWS accounts could expose organizational data and configuration information.

## Impact

Making an AMI private may affect other AWS accounts that depend on it. Ensure shared accounts are explicitly added if needed.

## Audit Procedure

### Using AWS CLI

No specific CLI audit command is provided for this control. Use the console method below.

### Using AWS Console

1. Login to the EC2 console at https://console.aws.amazon.com/ec2/.
2. In the left pane, under `Images`, click `AMIs`.
3. Confirm the `Owned by me` is set.
4. Select the AMI from the list.
5. Click on the `Permissions` Tab.
6. If this reads `This image is currently Public`, please refer to the remediation below.

## Expected Result

All AMIs should have their permissions set to Private. No AMI should display "This image is currently Public" in the Permissions tab.

## Remediation

### Using AWS CLI

No specific CLI remediation command is provided for this control. Use the console method below.

### Using AWS Console

1. Login to the EC2 console at https://console.aws.amazon.com/ec2/.
2. In the left pane, under `Images`, click `AMIs`.
3. Confirm the `Owned by me` is set.
4. Select the AMI from the list.
5. Click on the `Permissions` Tab.
6. Click on `Edit`.
7. Click on the radio button `Private`.

Add AWS Account Number if you have a need to share with other Internal AWS accounts that your Organization owns.

## Default Value

By default, AMIs are private when created. They must be explicitly made public.

## References

1. https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/sharing-amis.html

## CIS Controls

| Controls Version | Control                          | IG 1 | IG 2 | IG 3 |
| ---------------- | -------------------------------- | ---- | ---- | ---- |
| v8               | 11.3 Protect Recovery Data       | x    | x    | x    |
| v7               | 5.3 Securely Store Master Images |      | x    | x    |

## Profile

Level 1 | Manual
