Skip to main content

💼 5.7 Ensure that the EC2 Metadata Service only allows IMDSv2 (Automated)

  • Contextual name: 💼 5.7 Ensure that the EC2 Metadata Service only allows IMDSv2 (Automated)
  • ID: /frameworks/cis-aws-v4.0.0/05/07
  • Located in: 💼 5 Networking

Description

When enabling the Metadata Service on AWS EC2 instances, users have the option of using either Instance Metadata Service Version 1 (IMDSv1; a request/response method) or Instance Metadata Service Version 2 (IMDSv2; a session-oriented method).

Similar

  • Sections
    • /frameworks/cis-aws-v4.0.1/05/07
    • /frameworks/cis-aws-v3.0.0/05/06

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlags
💼 CIS AWS v3.0.0 → 💼 5.6 Ensure that EC2 Metadata Service only allows IMDSv2 - Level 1 (Automated)11
💼 CIS AWS v4.0.1 → 💼 5.7 Ensure that the EC2 Metadata Service only allows IMDSv2 (Automated)1

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlags
💼 CIS AWS v3.0.0 → 💼 5.6 Ensure that EC2 Metadata Service only allows IMDSv2 - Level 1 (Automated)11
💼 CIS AWS v4.0.1 → 💼 5.7 Ensure that the EC2 Metadata Service only allows IMDSv2 (Automated)1

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)

PolicyLogic CountFlags
📝 AWS EC2 Instance IMDSv2 is not enabled 🟢1🟢 x6