Mods
AWS

Policy: AWS > CIS v3.0 > 5 - Networking > 5.06 - Ensure that EC2 Metadata Service only allows IMDSv2

Configures auditing against a CIS Benchmark item.

Level: 1

When enabling the Metadata Service on AWS EC2 instances, users have the option of using either Instance Metadata Service Version 1 (IMDSv1; a request/response method) or Instance Metadata Service Version 2 (IMDSv2; a session-oriented method).

Resource Types

This policy targets the following resource types:

Primary Policy

This policy is used with the following primary policy:

Controls

Policy Specification

Schema Type
string
Default
Per AWS > CIS v3.0 > 5 - Networking
Valid Values [YAML]
  • Per AWS > CIS v3.0 > 5 - Networking
    
  • Skip
    
  • Check: Benchmark
    

Category

In Your Workspace

Developers