IOanyT Hardened Amazon Linux 2023 - CIS Level 1
Amazon Linux 2023 hardened to CIS Benchmark Level 1, with SELinux enforcing, in x86_64 and Graviton (arm64) editions.
Delivery method
AWS AMI
Operating system
Amazon Linux 2023
Architecture
x86_64 and arm64 (Graviton)
Released
October 8, 2026
What it is
IOanyT Hardened Amazon Linux 2023 is a ready-to-launch base operating system for AWS. It is Amazon Linux 2023 hardened to the CIS Benchmark Level 1, with a documented exceptions list.
It comes in two editions, x86_64 and Graviton (arm64), with the same hardening and the same price; choose the one that matches your instance type. SELinux stays enforcing. Each instance gets its own SSH host keys and machine identity on first boot, and builds its own file-integrity (AIDE) baseline a few minutes later. Security updates install automatically, and every release ships with its CIS audit results.
The charges cover hardening, maintenance and support by IOanyT Innovations.
Who it's for
Teams that need a hardened base operating system to build their own images and workloads on
Regulated environments (SOC 2, ISO 27001, PCI DSS) that want hardening evidence to start a security review
Platform teams that want x86_64 and Graviton (arm64) servers with the same hardening on both
Workloads that must keep everything inside their own AWS account and VPC
Why it's different
Hardened, with the exceptions written down
The image is hardened to CIS Benchmark Level 1. Where a control does not fit a cloud image, the exception and its reason are documented, not hidden.
Unique per instance
SSH host keys and the machine identity are created on your instance, so no two customers share a key.
Patched automatically
Security updates install automatically. You apply everything else with sudo dnf upgrade in your own maintenance window.
Evidence included
Every release ships with its CIS audit results, the documented exceptions list and a package inventory, so your security review starts with facts.
x86_64 and Graviton editions
Two editions, one per architecture, with the same price. Both are built from the same code and tested the same way before release.
Security & compliance
Amazon Linux 2023 hardened to CIS Benchmark Level 1 (applied with ansible-lockdown AMAZON2023-CIS 1.4.0), then checked with 410 automated audit tests. Every remaining finding is on the documented exceptions list.
SSH is key-only and limited to the ec2-user user. The root account is locked.
SELinux stays enforcing (targeted policy).
/tmp is a separate tmpfs mounted nodev,nosuid,noexec.
File integrity: AIDE builds a baseline on each instance a few minutes after first boot.
Automatic security updates are enabled.
IMDSv2 is required on the image.
Exceptions: the documented exceptions include the host firewall (use your EC2 security group instead), separate disk partitions (the image has a single root volume) and sending logs to your own log server. The full list ships with each release.
Shared responsibility: IOanyT hardens and maintains the image; you control network access (security groups), IAM, patching of everything beyond automatic security updates, and your workloads and data.
What's included
| Component | Detail |
|---|---|
| Operating system | Amazon Linux 2023 |
| Architectures | x86_64 and arm64 (Graviton), two editions (one Marketplace listing per architecture) |
| Hardening | CIS Benchmark Level 1, AMAZON2023-CIS 1.4.0, documented exceptions |
| Default login user | ec2-user |
| File integrity | AIDE, baseline built per instance |
| Automatic updates | dnf-automatic, security updates only |
| Evidence per release | CIS audit results, exceptions list, package inventory |
No applications are installed. This is a base operating system image.
Supported instance types
| Architecture | Instance types | Recommended |
|---|---|---|
| x86_64 | t3.medium to t3.2xlarge; m7i, c7i and r7i, large to 4xlarge | m7i.large |
| arm64 (Graviton) | t4g.medium to t4g.2xlarge; m7g, c7g and r7g, large to 4xlarge | m7g.large |
Ports
- 22/tcp — SSH. Open it from your own network only.
Pricing
Pay-as-you-go — $0.03/hr
Hourly (pay-as-you-go)
Software charge, billed through AWS Marketplace.
Annual subscription — about $199/yr
Annual contract
Billed through AWS Marketplace.
AWS infrastructure charges (EC2, EBS and so on) are billed separately. The price is flat across all supported instance types and is the same for the x86_64 and Graviton editions.
Refund policy: We don't support any refund policy but you can cancel anytime.
Frequently asked questions
How is it delivered?
As an Amazon Machine Image (AMI). You launch it in your own AWS account. There are two editions, each its own AWS Marketplace listing: x86_64 and Graviton (arm64). They have the same hardening and the same price. Choose the edition that matches your instance type.
How do I log in?
With SSH, as ec2-user, using the key pair you chose at launch. Password login is disabled and the root account is locked. Use sudo for administration.
Is it CIS certified?
No. It is hardened to CIS Benchmark Level 1 and audited with 410 automated checks. Controls that do not fit a single-disk cloud image are documented as exceptions with their reasons. The exceptions list and audit evidence ship with each release.
Is there a firewall on the instance?
No host firewall is configured. Network access is controlled by your EC2 security group. Allow SSH (22) from your own network only, never from 0.0.0.0/0.
Can I mount EFS/NFS or run Docker?
Not by default: CIS hardening disables some unused filesystem modules (NFS/EFS, FUSE and overlay). The deployment guide shows how to re-enable them.
When does the file-integrity baseline appear?
About 5 minutes after boot. The deployment guide shows how to check for it and run a check.
What support is included?
Email support from IOanyT, with a response within 1 business day.
Support
We reply within 1 business day.
Questions or issues? Email aws-marketplace-support@ioanyt.com.
Ready to deploy?
Launch a hardened Amazon Linux 2023 server in minutes. It runs entirely inside your AWS account.