Overview
The CIS Hardened Image Level 1 on Red Hat Enterprise Linux 8 is a pre-configured image built by the Center for Internet Security (CIS®) for use on Amazon Elastic Compute Cloud (Amazon EC2). It is a pre-configured, security-hardened image that aligns with the robust security recommendations, the CIS Benchmarks, making it easier for organizations to meet regulatory requirements.
Not only is this image pre-hardened to the CIS Benchmarks guidance, but it is also patched monthly in alignment with the updates from the software vendor.
Key Benefits
This image is hardened against the corresponding Level 1 profile which is intended to be practical and prudent, provide a clear security benefit, and not inhibit the utility of the technology beyond acceptable means. No packages are installed on or removed from this image outside of those already present on the base image or as recommended in alignment with the corresponding CIS Benchmark recommendations.
To demonstrate conformance to the CIS Red Hat Enterprise Linux 8 Level 1 Benchmark, industry-recognized hardening guidance, each image includes an HTML report from CIS Configuration Assessment Tool (CIS-CAT® Pro). Each CIS Hardened Image contains the following files:
These reports are located in /home/CIS_Hardened_Reports.
For customized pricing options or private offers, reach out to us at cloudsecurity@cisecurity.org .
To learn more or access the corresponding CIS Benchmark, please visit https://www.cisecurity.org/cis-benchmarks or sign up for a free account on our community platform, CIS WorkBench, https://workbench.cisecurity.org/ .
Highlights
- Hardened according to a Level 1 CIS Benchmark that is developed in a consensus-based process and that is accepted by government, business, industry, and academia.
- Helps with compliance to PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
- Pre-configured to align with industry best practices that are developed and supported by CIS, this image has hardened account and local policies, firewall configuration, and computer-based and user-based administrative templates.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
- ...
Dimension | Cost/hour |
|---|---|
t3.medium Recommended | $0.022 |
t2.micro | $0.02 |
t3.micro | $0.022 |
r5b.2xlarge | $0.026 |
r6a.4xlarge | $0.035 |
c5.18xlarge | $0.06 |
r7i.metal-24xl | $0.06 |
c7a.24xlarge | $0.06 |
m5a.large | $0.022 |
m7i.2xlarge | $0.026 |
Vendor refund policy
Refunds through AWS are not available at this time. You will only be billed for actual time of instance use. As with all CIS security products, our aim is always 100 percent customer/member satisfaction.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Monthly updates
Additional details
Usage instructions
No sensitive information supplied by customers will be stored outside this instance. No data encryption configuration is applicable to this instance. You can encrypt the instance EBS volume per standard EC2 processes. No programmatic system credentials and cryptographic keys are used by this instance. Launch the instance via the AWS Marketplace or EC2 console. Navigate to your Amazon EC2 console and verify that you're in the correct region. Choose instance and select your launched instance. Select the server to display your metadata page and choose the Status checks tab at the bottom of the page to review if your status checks passed or failed. Connect using SSH. Use ec2-user as the username. Immediately apply latest security updates to the instance.
Resources
Support
Vendor support
Questions, feedback, and support accessing CIS-developed AMIs is provided by contacting
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Integrated automation has reduced downtime and accelerated secure VM delivery for our teams
What is our primary use case?
My main use cases for Red Hat Enterprise Linux (RHEL) are for applications, primarily. We provide Red Hat Enterprise Linux (RHEL) to other teams because we are from the operations team and have infrastructure responsibilities. We provide Red Hat Enterprise Linux (RHEL) VMs for developers and other teams to run their applications on.
Before adopting Red Hat Enterprise Linux (RHEL), my company used many Windows VMs. From the time I have been working in the company, we have been a Linux shop with Red Hat Enterprise Linux (RHEL) VMs, along with a few Windows VMs.
What is most valuable?
Red Hat Enterprise Linux (RHEL) helps me solve pain points because Linux in general is easy to work with. The automation is straightforward. Because we have an ecosystem of Red Hat OpenShift , Ansible , and Red Hat Enterprise Linux (RHEL), the integration flows naturally.
The features of Red Hat Enterprise Linux (RHEL) that I prefer most are the security features, which are very useful. The domain join realm and SELinux are also excellent.
For navigating our security risks with Red Hat Enterprise Linux (RHEL), we currently use SELinux for security. We do not use Lightspeed at this time. We have FirewallD and other services for security. For identity management, we have our own Kerberos agents that we use for identity purposes.
Satellite helps maintain our environment overall because we have integration with Ansible and the Ansible Automation Platform. When we need to create a new VM, we start with Satellite and have all the bootstrap processes integrated with Ansible. The VM then comes up automatically, and we provide it to customers or whoever wants to use it.
Red Hat Enterprise Linux (RHEL) has helped me mitigate downtime and lower risks.
The capabilities of Red Hat Enterprise Linux (RHEL) that have assisted me with this are mainly the integration aspects, such as Satellite and the Ansible Automation Platform. Everything has helped us reduce downtime for customers and accelerate VM deployment.
What needs improvement?
The security portions of Red Hat Enterprise Linux (RHEL) could be improved and made easier to work with. SELinux in general is not intuitive because customers and developers do not know how to work with the VM. This part could be more user-friendly.
In my company's implementation of the Zero Trust model, we have not yet implemented this with Red Hat Enterprise Linux (RHEL). Because we are from the operations team, there is another team that handles other responsibilities. We do not necessarily handle that aspect.
For how long have I used the solution?
I have been using Red Hat Enterprise Linux (RHEL) for three years.
What do I think about the stability of the solution?
We have occasionally experienced downtime, crashes, or performance issues with Red Hat Enterprise Linux (RHEL), but not frequently. Overall, it has been reliable.
What do I think about the scalability of the solution?
Scalability-wise, the scaling process for Red Hat Enterprise Linux (RHEL) is smooth. We have scaled many applications and have not encountered any issues. The performance has been solid.
How are customer service and support?
I evaluate the customer service and technical support from Red Hat as very good. I have never had any issues with the technical support. I have created multiple tickets with the Red Hat team and they have been quick and effective at responding and fixing the issues. I would rate the customer service and technical support a nine out of ten.
Which solution did I use previously and why did I switch?
The advantages of having Red Hat Enterprise Linux (RHEL) instead of Windows servers are that the development process is easier. I think Windows is limiting. Linux in general provides more opportunity to try different approaches, work on different projects, and avoid being restricted to certain functionalities that are imposed on clients who use the operating system. Red Hat Enterprise Linux (RHEL) has done an excellent job overall.
How was the initial setup?
I would describe the experience of deploying Red Hat Enterprise Linux (RHEL) as straightforward. It is not complicated. We use Satellite to deploy the VMs and the process is very straightforward with minimal complexity.
What about the implementation team?
We have used the Ansible Automation Platform through a dedicated automation team who handles all the automation for us.
What was our ROI?
From a technical point of view, the biggest return on investment when using Red Hat Enterprise Linux (RHEL) is the integration aspect. Working with OpenShift and having VMs on it is very smooth. Even though some features are not intuitive, the integration is seamless.
Which other solutions did I evaluate?
My company has not considered switching to another solution that does the same thing as Red Hat Enterprise Linux (RHEL). We are committed to continuing with Red Hat Enterprise Linux (RHEL).
What other advice do I have?
I would assess the knowledge base offered by Red Hat Enterprise Linux (RHEL) as very good. I believe there could be more information available. Red Hat Enterprise Linux (RHEL) in general is excellent, but counterparts such as OpenShift could improve with respect to documentation and the knowledge base.
We performed a major version upgrade of Red Hat Enterprise Linux (RHEL) using the Leapp upgrade tool manually. Although the process has been automated, we have not used automation to upgrade many VMs. We successfully upgraded forty to fifty VMs from Red Hat Enterprise Linux (RHEL) version seven to eight and from eight to nine using the Leapp upgrade.
The advice I would give to other companies is that from the time of deployment until the customer uses the system, having a pipeline ready and integration prepared for every component makes it much easier to deploy and use Red Hat Enterprise Linux (RHEL). I would rate this product an eight out of ten overall.
Automation has reduced server issues and now supports reliable, standardized deployments
What is our primary use case?
My use cases for Red Hat Enterprise Linux (RHEL) at my company include application servers, infrastructure servers, web servers, and virtually every server type.
What is most valuable?
The features of Red Hat Enterprise Linux (RHEL) that I appreciate most are ease of automation and ease of deployment, particularly because we also use Satellite for deployment management. It scales well.
These features benefit my company by resulting in less time spent working on servers and issues and more uptime.
What needs improvement?
I have not identified any immediate areas for improvement in Red Hat Enterprise Linux (RHEL), as I cannot think of anything that there is not already a product for.
We have encountered some issues with the high availability clustering lately, and it seems that could use some refinement.
The deployment process for Red Hat Enterprise Linux (RHEL) has been somewhat rough around the edges to get it up and running with Kickstart, but once I have it dialed in, it is fantastic. The documentation for Kickstart can leave something to be desired sometimes, so that may be an area of improvement.
For how long have I used the solution?
I have been using Red Hat Enterprise Linux (RHEL) for almost ten years.
What do I think about the stability of the solution?
I have not experienced any downtime, crashes, or performance issues with the platform that were not caused by some kind of misconfiguration. The platform itself is solid.
What do I think about the scalability of the solution?
I have been able to scale and expand usage as my needs have grown.
How are customer service and support?
I assess the knowledge base offered by Red Hat Enterprise Linux (RHEL) as outstanding. The Red Hat Learning Subscription is great, and usually when we enter a ticket with Red Hat support, we can get a subject matter expert to help us resolve our issues.
I would rate the customer service and technical support as probably an eight out of ten. Sometimes when we enter a ticket, it takes some time to get to the level of technical resource we need, but once we get that resource, they almost always help us get a problem solved.
Which solution did I use previously and why did I switch?
When I came in, our department was already heavily using Red Hat Enterprise Linux (RHEL).
How was the initial setup?
The deployment process for Red Hat Enterprise Linux (RHEL) has been somewhat rough around the edges to get it up and running with Kickstart.
What was our ROI?
From a technical point of view, the biggest return on investment when using Red Hat Enterprise Linux (RHEL) is the stability and uptime.