IOanyT Innovations
AWS AMI Security v1.0.0

IOanyT Hardened Amazon Linux 2023 - CIS Level 1

Amazon Linux 2023 hardened to CIS Benchmark Level 1, with SELinux enforcing, in x86_64 and Graviton (arm64) editions.

Delivery method

AWS AMI

Operating system

Amazon Linux 2023

Architecture

x86_64 and arm64 (Graviton)

Released

October 8, 2026

Amazon Linux 2023 hardened to CIS Benchmark Level 1, with a documented exceptions list and audit evidence
SELinux enforcing; unique SSH host keys and machine identity per instance; key-only SSH
Automatic security updates and a per-instance AIDE file-integrity baseline, in both the x86_64 and Graviton editions

What it is

IOanyT Hardened Amazon Linux 2023 is a ready-to-launch base operating system for AWS. It is Amazon Linux 2023 hardened to the CIS Benchmark Level 1, with a documented exceptions list.

It comes in two editions, x86_64 and Graviton (arm64), with the same hardening and the same price; choose the one that matches your instance type. SELinux stays enforcing. Each instance gets its own SSH host keys and machine identity on first boot, and builds its own file-integrity (AIDE) baseline a few minutes later. Security updates install automatically, and every release ships with its CIS audit results.

The charges cover hardening, maintenance and support by IOanyT Innovations.

Who it's for

Teams that need a hardened base operating system to build their own images and workloads on

Regulated environments (SOC 2, ISO 27001, PCI DSS) that want hardening evidence to start a security review

Platform teams that want x86_64 and Graviton (arm64) servers with the same hardening on both

Workloads that must keep everything inside their own AWS account and VPC

Why it's different

Hardened, with the exceptions written down

The image is hardened to CIS Benchmark Level 1. Where a control does not fit a cloud image, the exception and its reason are documented, not hidden.

Unique per instance

SSH host keys and the machine identity are created on your instance, so no two customers share a key.

Patched automatically

Security updates install automatically. You apply everything else with sudo dnf upgrade in your own maintenance window.

Evidence included

Every release ships with its CIS audit results, the documented exceptions list and a package inventory, so your security review starts with facts.

x86_64 and Graviton editions

Two editions, one per architecture, with the same price. Both are built from the same code and tested the same way before release.

Security & compliance

Amazon Linux 2023 hardened to CIS Benchmark Level 1 (applied with ansible-lockdown AMAZON2023-CIS 1.4.0), then checked with 410 automated audit tests. Every remaining finding is on the documented exceptions list.

SSH is key-only and limited to the ec2-user user. The root account is locked.

SELinux stays enforcing (targeted policy).

/tmp is a separate tmpfs mounted nodev,nosuid,noexec.

File integrity: AIDE builds a baseline on each instance a few minutes after first boot.

Automatic security updates are enabled.

IMDSv2 is required on the image.

Exceptions: the documented exceptions include the host firewall (use your EC2 security group instead), separate disk partitions (the image has a single root volume) and sending logs to your own log server. The full list ships with each release.

Shared responsibility: IOanyT hardens and maintains the image; you control network access (security groups), IAM, patching of everything beyond automatic security updates, and your workloads and data.

What's included

Component Detail
Operating system Amazon Linux 2023
Architectures x86_64 and arm64 (Graviton), two editions (one Marketplace listing per architecture)
Hardening CIS Benchmark Level 1, AMAZON2023-CIS 1.4.0, documented exceptions
Default login user ec2-user
File integrity AIDE, baseline built per instance
Automatic updates dnf-automatic, security updates only
Evidence per release CIS audit results, exceptions list, package inventory

No applications are installed. This is a base operating system image.

Supported instance types

Architecture Instance types Recommended
x86_64 t3.medium to t3.2xlarge; m7i, c7i and r7i, large to 4xlarge m7i.large
arm64 (Graviton) t4g.medium to t4g.2xlarge; m7g, c7g and r7g, large to 4xlarge m7g.large

Ports

  • 22/tcp — SSH. Open it from your own network only.

Pricing

Pay-as-you-go — $0.03/hr

Hourly (pay-as-you-go)

Software charge, billed through AWS Marketplace.

Annual subscription — about $199/yr

Annual contract

Billed through AWS Marketplace.

AWS infrastructure charges (EC2, EBS and so on) are billed separately. The price is flat across all supported instance types and is the same for the x86_64 and Graviton editions.

Refund policy: We don't support any refund policy but you can cancel anytime.

Frequently asked questions

How is it delivered?

As an Amazon Machine Image (AMI). You launch it in your own AWS account. There are two editions, each its own AWS Marketplace listing: x86_64 and Graviton (arm64). They have the same hardening and the same price. Choose the edition that matches your instance type.

How do I log in?

With SSH, as ec2-user, using the key pair you chose at launch. Password login is disabled and the root account is locked. Use sudo for administration.

Is it CIS certified?

No. It is hardened to CIS Benchmark Level 1 and audited with 410 automated checks. Controls that do not fit a single-disk cloud image are documented as exceptions with their reasons. The exceptions list and audit evidence ship with each release.

Is there a firewall on the instance?

No host firewall is configured. Network access is controlled by your EC2 security group. Allow SSH (22) from your own network only, never from 0.0.0.0/0.

Can I mount EFS/NFS or run Docker?

Not by default: CIS hardening disables some unused filesystem modules (NFS/EFS, FUSE and overlay). The deployment guide shows how to re-enable them.

When does the file-integrity baseline appear?

About 5 minutes after boot. The deployment guide shows how to check for it and run a check.

What support is included?

Email support from IOanyT, with a response within 1 business day.

Support

We reply within 1 business day.

Questions or issues? Email aws-marketplace-support@ioanyt.com.

Ready to deploy?

Launch a hardened Amazon Linux 2023 server in minutes. It runs entirely inside your AWS account.