Skip to main content

πŸ’Ό 5.6 Ensure that EC2 Metadata Service only allows IMDSv2 - Level 1 (Automated)

  • Contextual name: πŸ’Ό 5.6 Ensure that EC2 Metadata Service only allows IMDSv2 - Level 1 (Automated)
  • ID: /frameworks/cis-aws-v2.0.0/05/06
  • Located in: πŸ’Ό 5 Networking

Description​

When enabling the Metadata Service on AWS EC2 instances, users have the option of using either Instance Metadata Service Version 1 (IMDSv1; a request/response method) or Instance Metadata Service Version 2 (IMDSv2; a session-oriented method).

Similar​

  • Sections
    • /frameworks/cis-aws-v3.0.0/05/06
  • Internal
    • ID: dec-c-125bff0f

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS AWS v3.0.0 β†’ πŸ’Ό 5.6 Ensure that EC2 Metadata Service only allows IMDSv2 - Level 1 (Automated)11

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS AWS v3.0.0 β†’ πŸ’Ό 5.6 Ensure that EC2 Metadata Service only allows IMDSv2 - Level 1 (Automated)11

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)​

PolicyLogic CountFlags
πŸ“ AWS EC2 Instance IMDSv2 is not enabled 🟒1🟒 x6

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-b42fae781