Listing Thumbnail

    CIS Hardened Container Image Level 1 on Ubuntu Linux 22.04 LTS

     Info
    Deployed on AWS
    This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.

    Overview

    CIS Hardened Container Image Level 1 on Ubuntu Linux 22.04 LTS is a pre-configured container image built by the Center for Internet Security (CIS®) to run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). It is a pre-configured, security-hardened image that aligns with the robust security recommendations, the CIS Benchmarks, making it easier for organizations to meet regulatory requirements.

    Not only is this container image pre-hardened to the CIS Benchmarks guidance, but it is also patched monthly in alignment with the updates from the software vendor.

    Key Benefits

  • Enhanced Security: Mitigates risks like malware, denial of service, and authorization issues by following globally-recognized secure configuration guidance to support your cloud security posture management (CSPM) program.
  • Compliance Readiness: Helps your organization comply with PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
  • Faster Deployment: Pre-configured according to CIS Benchmarks, allowing you to deploy secure virtual machine images.
  • Consistency Across Environments: Ensures consistent security configurations across development, testing, and production environments, reducing drift and compatibility risks.
  • Cost Efficiency: Lowers remediation efforts, reduces attack surface, and minimizes business loss from security incidents.
  • Easier Maintenance: Regular updates ensure that your systems are always in line with the latest security standards and software patches.

    This container image is hardened against the corresponding Level 1 profile which is intended to be practical and prudent, provide a clear security benefit, and not inhibit the utility of the technology beyond acceptable means. No packages are installed on or removed from this image outside of those already present on the base image or as recommended in alignment with the corresponding CIS Benchmark recommendations.

    To demonstrate conformance to the CIS Ubuntu Linux 22.04 LTS Level 1 Benchmark, industry-recognized hardening guidance, each image includes an HTML report from CIS Configuration Assessment Tool (CIS-CAT® Pro). Each CIS Hardened Image contains the following files:

  • Base_CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance before any change is made by CIS (e.g., software updates, CIS hardening).
  • basevm.txt - this provides a list of the packages resident on the instance prior to any change being made by CIS (e.g., software updates, CIS hardening).
  • CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance after the corresponding CIS Benchmark was applied to the image.
  • Exceptions.txt - this provides a list of recommendations that are not applied because the configuration of those recommendations may inhibit the use of this image in this CSP, require environment-specific expertise, or hinder the integration of this image with CSP services or extensions.
  • afterhardening.txt - this provides a list of packages resident on the instance after the corresponding CIS Benchmark was applied to the image.

    These reports are located in /home/CIS_Hardened_Reports.

    For customized pricing options or private offers, reach out to us at cloudsecurity@cisecurity.org .

    To learn more or access the corresponding CIS Benchmark, please visit https://www.cisecurity.org/cis-benchmarks  or sign up for a free account on our community platform, CIS WorkBench, https://workbench.cisecurity.org/ .

  • Highlights

    • Hardened according to a Level 1 CIS Benchmark that is developed in a consensus-based process and that is accepted by government, business, industry, and academia.
    • Helps with compliance to PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
    • Pre-configured to align with industry best practices that are developed and supported by CIS, this image has hardened account and local policies, firewall configuration, and computer-based and user-based administrative templates.

    Details

    Delivery method

    Supported services

    Delivery option
    CIS Ubuntu Linux 22.04 LTS Benchmark L1 Container Image

    Latest version

    Operating system
    Linux

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    CIS Hardened Container Image Level 1 on Ubuntu Linux 22.04 LTS

     Info
    Pricing is based on a fixed subscription cost. You pay the same amount each billing period for unlimited usage of the product. Pricing is prorated, so you're only charged for the number of days you've been subscribed. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Fixed subscription cost

     Info
    $38.00/month

    Vendor refund policy

    This is a placeholder value. Please update this value via the AWS Marketplace Management Portal.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    CIS Ubuntu Linux 22.04 LTS Benchmark L1 Container Image

    Supported services: Learn more 
    • Amazon ECS
    • Amazon EKS
    Container image

    Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.

    Version release notes

    Monthly product updates

    Additional details

    Usage instructions

    Launch this container using the provided ECS, EKS or any of the Pull commands provide by AWS. Once you pull it down utilize a Dockerfile and build off this CIS Hardened Container Image. More documentation with reference to utilizing ECS and EKS can be found at https://aws.amazon.com/ecs/ .

    Support

    Vendor support

    Questions, feedback, and support accessing CIS-developed Container Images is provided by contacting

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Compliance and Auditing, Operating Systems, Security

    Overview

     Info
    AI generated from product descriptions
    Security Hardening
    Pre-configured container image hardened against CIS Benchmarks Level 1 profile with comprehensive security configurations
    Compliance Assessment
    Includes CIS Configuration Assessment Tool (CIS-CAT Pro) reports for demonstrating conformance to security benchmarks
    Benchmark Alignment
    Follows industry-recognized security recommendations developed through consensus-based process by CIS
    Configuration Reporting
    Provides detailed HTML reports and text files documenting system configuration before and after hardening
    Platform Compatibility
    Designed to run on container runtimes and orchestration services like Amazon ECS and Amazon EKS
    Cryptographic Compliance
    FIPS 140-2 certified kernel and cryptographic modules with out-of-the-box compliance
    Security Patch Coverage
    Comprehensive security updates for over 23,000 open source packages across Ubuntu Universe repository
    Compliance Hardening
    Integrated hardening profiles from CIS and DISA-STIG security implementation guidelines
    Kernel Security
    FIPS-certified kernel with ongoing security updates for cryptographic components
    Security Tooling
    Ubuntu Security Guide (USG) for automated compliance and security configuration management
    Security Configuration
    Pre-configured security safeguards with minimized attack surfaces and default protective measures
    Compliance Framework
    Vendor-neutral security configuration aligned with multiple cybersecurity compliance standards
    System Optimization
    Preconfigured Linux system tailored for system administrators, security experts, and platform deployment professionals
    Security Standard Adherence
    Image developed through consensus-based approach following industry-recognized security benchmarks

    Contract

     Info
    Standard contract
    No

    Customer reviews

    Ratings and reviews

     Info
    4.3
    3 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    3 AWS reviews
    |
    36 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Martin Prous

    Discovering extensive documentation and seamless software integration elevates daily operations

    Reviewed on Jun 23, 2025
    Review provided by PeerSpot

    What is our primary use case?

    Ubuntu Linux is my operating system for daily use, and because I am related to networking operations, I prefer Linux over Windows. The FortiClient in Windows is very limiting and the IT department most of the time doesn't know how to open certain ports or are very limited in their skills with FortiClient, so I have more freedom to open ports and run some services with it.

    What is most valuable?

    One of the best features of Ubuntu Linux is that if I need something, I just download it. Everything I need I could search for on the net and just download it and use it, whereas Windows is more problematic.

    Ubuntu Linux's rapid support and extensive documentation are fine to me. Every time I need to do something, I find well-explained documentation about the process, so I have no complaints about the documentation or the info about how to do it.

    What needs improvement?

    I always use just the LTS versions of Ubuntu Linux, but I found recently some software that needs the 20.04 version, which is out of the support lifecycle, and those systems are needed by us, causing a problem when I tried to upgrade. The systems stopped working and it was a disaster, as they support the LTS but the old ones, and when I need to update some packages, they are out of the support system support cycle.

    For how long have I used the solution?

    I have used Ubuntu Linux for maybe 12 years.

    How are customer service and support?

    I have never rated the support or customer service of Ubuntu Linux as I have never used it.

    How would you rate customer service and support?

    Positive

    What's my experience with pricing, setup cost, and licensing?

    My experience with the pricing for Ubuntu Linux is that I always use the free version, so I never paid for any installations or support.

    What other advice do I have?

    I have not used Ubuntu Linux's cloud-init capabilities for configuring or managing instances in cloud environments.

    I don't know of any things that could be better with Ubuntu Linux, as everything works fine.

    On a scale of one to ten, I would rate Ubuntu Linux a 10 plus.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2728158

    Good compatibility and improvement needed in migration process

    Reviewed on Jun 23, 2025
    Review from a verified AWS customer

    What is our primary use case?

    I basically work only in Linux because I'm a Linux system administrator, so I preferably only work in Linux systems.

    I'm basically a system admin in the Linux domain, and I work in EC2 instances only. My work revolves around Drupal websites, as I work in an organization that primarily focuses on Drupal websites. To run those Drupal websites, we use EC2 instances as our server, so that is the main expertise I have.

    I am not exactly in development because I'm in operations, but that can come into the role itself because I'm involved in operations, not the development team itself.

    What is most valuable?

    I am currently using Ubuntu Linux internally in my company, and for customers too.

    For long-term support, it has been good because in most enterprise environments, people still use Ubuntu Linux sixteen, which is quite obsolete now. Other enterprise versions do not support obsolete systems, so supportability is good in terms of Ubuntu Linux. For sustainability, it's quite a significant point of view for every organization. For us, Ubuntu Linux is the preferable way.

    The documentation for Ubuntu Linux is quite extensive; you'll gain the information that we intend to, but you need to have the ability to navigate through the documents. That's very good knowledge that they provide, and that's a solid point from me.

    Most people prefer Ubuntu Linux. If they want any specific tooling, such as SAP applications, people use SUSE or Red Hat for specific hybrid infrastructures related to security. If people want reliability and flexibility to run anything, they use Ubuntu Linux. Compatibility with hardware is very good with Ubuntu Linux; I have seen very few issues regarding compatibility.

    The first advantage is that it's price-efficient as far as the enterprise version is concerned. There's not a very big difference, but if you are running ten to twenty thousand fleets, those few dollars could mean a lot for some organizations. The second advantage is compatibility with any hardware, and the third is reliable OS updates and support.

    Any Linux is scalable in terms of capacity, and on a day-to-day basis, we use scalability options with the help of Kubernetes clusters. It's very convenient to scale it up to any form needed because Ubuntu Linux itself is a lightweight OS.

    What needs improvement?

    For long-term support, it has been good because in most enterprise environments, people still use Ubuntu Linux sixteen, which is quite obsolete now. Other enterprise versions do not support obsolete systems, so supportability is good in terms of Ubuntu Linux. For sustainability, it's quite a significant point of view for every organization. For us, Ubuntu Linux is the preferable way. For others, it might not be, so that is quite a subjective matter itself.

    The pinpoint of the problem is that they take time because they need specific information. We need to go to AWS first, and then they'll contact the Ubuntu Linux support team itself. This creates a two-way hop for us, which is why it's not that great. It's not really Ubuntu Linux's problem but rather the way we are accessing Ubuntu Linux.

    The migration part when migrating an application or one version of Ubuntu Linux to another is quite hectic. During the process, one or many applications might crash. That is something they could handle themselves, but I don't think that's something Ubuntu Linux will look into. During a migration project that I was handling, Ubuntu Linux was not completely compatible for the migration process from one application to another. This is an area they could improve in migrating from minor versions to major versions.

    For how long have I used the solution?

    I have been working with Ubuntu Linux for three years now, and I've used different flavors from sixteen to twenty-two, and now it's the latest focal, which is twenty-five.

    What do I think about the stability of the solution?

    For me, it's quite simple because we don't frequently update the stack itself. For many people, it is subjective because if you're running very dynamic applications, not only on Ubuntu Linux but any Linux systems, it can be quite subjective based on the applications they are using. If updates happen frequently, no system would be stable without tuning it every time there's an update. For us, it's quite reliable in terms of stability.

    What do I think about the scalability of the solution?

    Any Linux is scalable in terms of capacity, and on a day-to-day basis, we use scalability options with the help of Kubernetes clusters. It's very good as there is no technical reasoning against it because Ubuntu Linux itself is a lightweight OS, so it's very convenient to scale it up to any form needed.

    How are customer service and support?

    The main issue is that they take time because they need specific information. We need to go to AWS first, and then they'll contact the Ubuntu Linux support team itself. This creates a two-way hop for us, which is why it's not that great. It's not really Ubuntu Linux's problem but rather the way we are accessing Ubuntu Linux.

    How would you rate customer service and support?

    Positive

    What other advice do I have?

    I would rate Ubuntu Linux a 9 out of 10. Any Linux is scalable in terms of capacity, and on a day-to-day basis, we use scalability options with the help of Kubernetes clusters. It's very good as there is no technical reasoning against it because Ubuntu Linux itself is a lightweight OS, so it's very convenient to scale it up to any form needed.

    The migration part when migrating an application or one version of Ubuntu Linux to another is quite hectic. During the process, one or many applications might crash. That is something they could handle themselves, but I don't think that's something Ubuntu Linux will look into. During a migration project that I was handling, Ubuntu Linux was not completely compatible for the migration process from one application to another. This is an area they could improve in migrating from minor versions to major versions.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    PrashantSharma

    Performs efficiently but requires overcoming a learning curve

    Reviewed on Jun 05, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I am mostly dealing with Ubuntu Linux  systems currently. Instead of using Windows, we have been given Ubuntu Linux , and that is what we have been using for our day-to-day activities. When we were due for an update, we switched from Windows to Ubuntu Linux, which has been a few months ago.

    What is most valuable?

    I believe everything works faster than it used to in Windows. I have never experienced a crash on Ubuntu Linux. The system works great with perfect stability.

    What needs improvement?

    There were some initial issues with logging into the system, but I do not remember much about them now. Currently, there are no issues. I do not think Ubuntu Linux has a robust documentation library.

    For how long have I used the solution?

    I am probably not in a place to say much about this as I have only been using it for a few months.

    What do I think about the stability of the solution?

    I have never experienced a crash on Ubuntu Linux. The system has been completely stable, which makes it deserve a perfect score. The system works great without any crashes.

    How are customer service and support?

    IT helps at times, so that is who we reach out to. It was our IT support person who helped us out. We have never had to reach out to Ubuntu Linux directly.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have not been working with Microsoft products recently. I have been working with other tools. I have not touched any Microsoft tools this year. Last year, I used Microsoft products minimally.

    What was our ROI?

    I am not sure about the return on investment. The higher-ups would likely know if they saved money since Microsoft is licensed while Ubuntu Linux does not require a license.

    What other advice do I have?

    There are many differences between Ubuntu Linux and Windows as they are totally different systems. You need to have more knowledge about Linux before using Ubuntu Linux. Although it is designed as a desktop system, basic knowledge is still required. Windows can be used by any layman, which is the main difference.

    I do not know much about security breaches or potential issues. The Wi-Fi and wireless capabilities work perfectly fine.

    Excluding the learning curve, I would rate it a 10. However, considering the learning curve, I would give it a six or seven.

    My advice would be to have patience.

    Overall rating: 10 out of 10.

    Kadir Kokcu

    Supports a wide range of features and offers a highly stable user experience

    Reviewed on May 14, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I use Ubuntu Linux  for application servers in my daily operations.

    I run web applications on Ubuntu Linux .

    For application servers, I find Ubuntu Linux very useful.

    I have a project on Ubuntu Linux that uses Nvidia graphic cards for AI purposes, such as Google Maps, where car cameras collect images while running on the road to build a map and recognize shop names and locations.

    What is most valuable?

    I find Ubuntu Linux to be a stable operating system and open-source, supporting almost all features as expected for an operating system, and it's widely supported by any open-source applications.

    It is widely supported by almost all applications.

    Ubuntu Linux continuously improves itself; it supports almost every new feature, and AI projects benefit from these developments, as well as every web-based project due to support for at least three or four web platforms such as Apache and Nginx.

    What needs improvement?

    Automation is very important for wide deployments, and Ubuntu Linux supports a lot of automation features, making it easy to deploy hundreds of applications. While Linux platforms are generally difficult to manage due to shell applications and lots of text files, automation handles these challenges and allows monitoring of the deployment process. This kind of development needs to be done, and the GUI could be better.

    The GUI could be improved for beginner users.

    For beginners, the GUI may be improved, but pro users use automation tools, scripts, and other options, so they don't need easy GUI tricks.

    For how long have I used the solution?

    I have been using Ubuntu Linux for at least 5 years.

    What was my experience with deployment of the solution?

    The initial setup deployment takes less than an hour.

    What do I think about the stability of the solution?

    During these 5 years, I have faced some minor issues with Ubuntu Linux, but not a major downtime.

    What do I think about the scalability of the solution?

    Ubuntu Linux is very scalable.

    Which solution did I use previously and why did I switch?

    Before working with Ubuntu Linux, I evaluated most other Linux operating systems such as Red Hat, SUSE, and others.

    Red Hat is a very professional operating system, and many operating systems use Red Hat-based code, but I find Ubuntu Linux to be a bit easier and more widely used, possibly due to Red Hat's license limitations.

    How was the initial setup?

    For the setup of Ubuntu Linux, I would rate it eight out of ten for ease.

    What's my experience with pricing, setup cost, and licensing?

    Ubuntu Linux is almost free, but it has some professional services that require payment if you choose to use them. For a low-cost application server, Ubuntu Linux is a good choice, or for an enterprise-wide scalable operating system with professional services, you can select Ubuntu Linux at a reasonable price.

    Which other solutions did I evaluate?

    I may share a review on other Linux or operating systems such as Rocky, Kali, Oracle, and SUSE in one or two months.

    What other advice do I have?

    Currently, approximately 2,000 users are working with Ubuntu Linux in my company.

    I plan to increase the usage in the future.

    I strongly recommend Ubuntu Linux to most customers.

    I would recommend it because it is very stable, supports almost every new feature, and almost all open-source projects, with easy support available from the web and professionals.

    I rate Ubuntu Linux 9 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Azaz Qurershi

    Using workstation features effectively with enhanced security

    Reviewed on May 14, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I use Ubuntu Linux  as a workstation to check my emails, to connect to people, to use Teams, to send mails, and to browse everything, similar to how we use Windows.

    I use Ubuntu Linux  as a replacement for Windows for everything. I use Teams, emails, Zoom , AnyDesk , and UltraViewer on it.

    What is most valuable?

    For system administration, I find it useful to connect to my Linux servers directly from the command line, and I create my virtual machines using VMware Workstation .

    In terms of security, I am satisfied with Ubuntu Linux and I can rely on its security features more than I can with Windows.

    What needs improvement?

    There might be some features or limitations I would want to see improved, but I cannot think of any specific ones right now. It is easy to use.

    The booting of Ubuntu Linux should be faster because I only have two minutes when I have calls, so it should complete more quickly.

    For how long have I used the solution?

    I have been working with Ubuntu Linux for four years.

    What was my experience with deployment of the solution?

    I have not faced any challenges with Ubuntu Linux such as integration or any other challenges.

    What do I think about the stability of the solution?

    I have not faced any challenges with Ubuntu Linux such as integration or any other challenges.

    What do I think about the scalability of the solution?

    I have not faced any challenges with Ubuntu Linux such as integration or any other challenges.

    What other advice do I have?

    I have not used Ubuntu Linux for AI as yet. My total rating for Ubuntu Linux is 9.

    View all reviews