IOanyT Hardened Ubuntu 24.04 - CIS Level 1
Ubuntu 24.04 LTS hardened to CIS Benchmark Level 1, in x86_64 and Graviton (arm64) editions, with a unique identity on every instance.
Delivery method
AWS AMI
Operating system
Ubuntu 24.04 LTS
Architecture
x86_64 and arm64 (Graviton)
Released
October 8, 2026
What it is
IOanyT Hardened Ubuntu 24.04 is a ready-to-launch base operating system for AWS. It is Ubuntu 24.04 LTS hardened to the CIS Benchmark Level 1, with a documented exceptions list.
It comes in two editions, x86_64 and Graviton (arm64), with the same hardening and the same price; choose the one that matches your instance type. Each instance gets its own SSH host keys, machine identity and TLS key on first boot, and builds its own file-integrity (AIDE) baseline a few minutes later. Security updates install automatically, and every release ships with its CIS audit results.
Ubuntu is open-source software; the charges cover hardening, maintenance and support by IOanyT Innovations.
Who it's for
Teams that need a hardened base operating system to build their own images and workloads on
Regulated environments (SOC 2, ISO 27001, PCI DSS) that want hardening evidence to start a security review
Platform teams that want x86_64 and Graviton (arm64) servers with the same hardening on both
Workloads that must keep everything inside their own AWS account and VPC
Why it's different
Hardened, with the exceptions written down
The image is hardened to CIS Benchmark Level 1. Where a control does not fit a cloud image, the exception and its reason are documented, not hidden.
Unique per instance
SSH host keys, the machine identity and the default TLS key are created on your instance, so no two customers share a key.
Patched automatically
Security updates install automatically. You apply everything else with sudo apt update && sudo apt upgrade in your own maintenance window.
Evidence included
Every release ships with its CIS audit results, the documented exceptions list and a package inventory, so your security review starts with facts.
x86_64 and Graviton editions
Two editions, one per architecture, with the same price. Both are built from the same code and tested the same way before release.
Security & compliance
Ubuntu 24.04 LTS hardened to CIS Benchmark Level 1 (applied with ansible-lockdown UBUNTU24-CIS 1.7.0), then checked with 591 automated audit tests. Every remaining finding is on the documented exceptions list.
SSH is key-only and limited to the ubuntu user. The root account is locked.
AppArmor: no profile is left loaded as unconfined.
Unique machine identity and TLS key per instance; no private key is shared between instances.
/tmp is a separate tmpfs mounted nodev,nosuid,noexec.
File integrity: AIDE builds a baseline on each instance a few minutes after first boot.
Automatic security updates are enabled.
IMDSv2 is required on the image.
Exceptions: the documented exceptions include the host firewall (use your EC2 security group instead), separate disk partitions (the image has a single root volume) and sending logs to your own log server. The full list ships with each release.
Shared responsibility: IOanyT hardens and maintains the image; you control network access (security groups), IAM, patching of everything beyond automatic security updates, and your workloads and data.
What's included
| Component | Detail |
|---|---|
| Operating system | Ubuntu 24.04 LTS |
| Architectures | x86_64 and arm64 (Graviton), two editions (one Marketplace listing per architecture) |
| Hardening | CIS Benchmark Level 1, UBUNTU24-CIS 1.7.0, documented exceptions |
| Default login user | ubuntu |
| File integrity | AIDE, baseline built per instance |
| Automatic updates | unattended-upgrades, security updates only |
| Evidence per release | CIS audit results, exceptions list, package inventory |
No applications are installed. This is a base operating system image.
Supported instance types
| Architecture | Instance types | Recommended |
|---|---|---|
| x86_64 | t3.medium to t3.2xlarge; m7i, c7i and r7i, large to 4xlarge | m7i.large |
| arm64 (Graviton) | t4g.medium to t4g.2xlarge; m7g, c7g and r7g, large to 4xlarge | m7g.large |
Ports
- 22/tcp — SSH. Open it from your own network only.
Pricing
Pay-as-you-go — $0.03/hr
Hourly (pay-as-you-go)
Software charge, billed through AWS Marketplace.
Annual subscription — about $199/yr
Annual contract
Billed through AWS Marketplace.
AWS infrastructure charges (EC2, EBS and so on) are billed separately. The price is flat across all supported instance types and is the same for the x86_64 and Graviton editions.
Refund policy: We don't support any refund policy but you can cancel anytime.
Frequently asked questions
How is it delivered?
As an Amazon Machine Image (AMI). You launch it in your own AWS account. There are two editions, each its own AWS Marketplace listing: x86_64 and Graviton (arm64). They have the same hardening and the same price. Choose the edition that matches your instance type.
How do I log in?
With SSH, as ubuntu, using the key pair you chose at launch. Password login is disabled and the root account is locked. Use sudo for administration.
Is it CIS certified?
No. It is hardened to CIS Benchmark Level 1 and audited with 591 automated checks. Controls that do not fit a single-disk cloud image are documented as exceptions with their reasons. The exceptions list and audit evidence ship with each release.
Is there a firewall on the instance?
No host firewall is configured. Network access is controlled by your EC2 security group. Allow SSH (22) from your own network only, never from 0.0.0.0/0.
Can I mount EFS/NFS or run Docker?
Not by default: CIS hardening disables some unused filesystem modules (NFS/EFS, FUSE and the Docker overlay module). The deployment guide shows how to re-enable them.
When does the file-integrity baseline appear?
About 5 minutes after boot. The deployment guide shows how to check for it and run a check.
What support is included?
Email support from IOanyT, with a response within 1 business day.
Support
We reply within 1 business day.
Questions or issues? Email aws-marketplace-support@ioanyt.com.
Ready to deploy?
Launch a hardened Ubuntu 24.04 LTS server in minutes. It runs entirely inside your AWS account.