Skip to main content

💼 5.6 Ensure that EC2 Metadata Service only allows IMDSv2 - Level 1 (Automated)

  • Contextual name: 💼 5.6 Ensure that EC2 Metadata Service only allows IMDSv2 - Level 1 (Automated)
  • ID: /frameworks/cis-aws-v3.0.0/05/06
  • Located in: 💼 5 Networking

Description

When enabling the Metadata Service on AWS EC2 instances, users have the option of using either Instance Metadata Service Version 1 (IMDSv1; a request/response method) or Instance Metadata Service Version 2 (IMDSv2; a session-oriented method).

Similar

  • Sections
    • /frameworks/cis-aws-v4.0.0/05/07
    • /frameworks/cis-aws-v2.0.0/05/06
  • Internal
    • ID: dec-c-63b757ce

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlags
💼 CIS AWS v2.0.0 → 💼 5.6 Ensure that EC2 Metadata Service only allows IMDSv2 - Level 1 (Automated)11
💼 CIS AWS v4.0.0 → 💼 5.7 Ensure that the EC2 Metadata Service only allows IMDSv2 (Automated)1

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlags
💼 CIS AWS v2.0.0 → 💼 5.6 Ensure that EC2 Metadata Service only allows IMDSv2 - Level 1 (Automated)11
💼 CIS AWS v4.0.0 → 💼 5.7 Ensure that the EC2 Metadata Service only allows IMDSv2 (Automated)1

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)

PolicyLogic CountFlags
📝 AWS EC2 Instance IMDSv2 is not enabled 🟢1🟢 x6

Internal Rules

RulePoliciesFlags
✉️ dec-x-b42fae781