This product has charges associated with it for DISA STIG security hardening. Madarson IT pre-hardened SUSE Linux Enterprise Server 16 AMI aligned with DISA STIG controls for federal, DoD, and high-security AWS cloud workloads requiring ATO readiness.
This is a repackaged software product wherein additional charges apply for DISA STIG security hardening.
Madarson IT SUSE Linux Enterprise Server 16 - DISA STIG Hardened AMI
This AWS EC2 image delivers SUSE Linux Enterprise Server 16 pre-hardened to align with Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs). Designed for federal agencies, defense contractors, and organizations operating in regulated environments, this image reduces the manual effort of STIG remediation and accelerates your path to an Authority to Operate (ATO).
What You Get
DISA STIG-Aligned Configuration: System settings, services, and access controls pre-configured to address DISA technical security requirements for SUSE Linux Enterprise Server.
DoD-Standard Login Banner: Compliant warning banner displayed at login as required by DoD environments.
Immutable Audit Configuration: Audit rules locked down to prevent tampering, supporting continuous monitoring and forensic readiness.
Hardened SSH: SSH configured with restricted ciphers, key-based authentication enforcement, and session timeout controls.
Restricted Services: Non-essential services disabled by default to minimize the attack surface.
Strict Access Controls: Role-based permissions and privilege escalation restrictions enforced out of the box.
Who This Is For
Federal agencies and DoD organizations requiring STIG-validated operating systems
Defense contractors preparing systems for ATO under the Risk Management Framework (RMF)
Organizations subject to FISMA, NIST 800-53, or other federal security mandates
Cloud teams seeking a secure baseline for high-assurance AWS workloads
How It Helps
Manually hardening a SUSE Linux Enterprise Server instance to meet DISA STIG requirements involves reviewing and remediating hundreds of individual controls across system configuration, access management, auditing, and network settings. This image ships with those controls pre-applied, allowing your team to focus on mission-specific configuration and residual risk assessment rather than baseline hardening.
By starting from a hardened baseline, organizations can reduce the number of open findings during compliance scans, shorten the timeline from deployment to ATO submission, and maintain a consistent security posture across their fleet.
Getting Started
Subscribe to this product on AWS Marketplace
Launch the AMI in your target VPC using a supported EC2 instance type
Connect via SSH using your configured key pair
Verify the DoD login banner appears upon connection
Run a SCAP compliance scan to validate the hardening baseline
Document any residual findings that require site-specific configuration
Deploy your workload on the hardened foundation
Compliance Frameworks Supported
DISA STIGs (SUSE Linux Enterprise Server)
FISMA
NIST Risk Management Framework (RMF)
NIST 800-53 security controls
Why Madarson IT
Madarson IT images are built for regulated cloud environments. Each image follows DISA STIG guidance and is designed for rapid deployment in federal and defense settings. Images are continuously updated to reflect new STIG releases and security patches, helping organizations maintain compliance over time.
Madarson IT also offers hardened and custom images across AWS, GCP, and Azure Marketplace, covering multiple operating systems and compliance frameworks.
Requirements and Limitations
This is a repackaged software product with additional charges for DISA STIG security hardening.
Buyers should verify compatibility with their target EC2 instance types before deploying at scale.
Application-layer STIGs and any CAT I findings requiring manual action remain the buyer's responsibility.
DISA STIG compliance requires more than technical controls at the operating system layer. Customers remain responsible for organizational, procedural, and additional infrastructure controls.
Buyers should run their own SCAP scan post-launch to validate compliance in their specific environment and document results for their accreditation package.
About Madarson IT
Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Our DISA STIG-hardened images help organizations meet federal cybersecurity requirements efficiently and reliably.
Disclaimer
SUSE and SUSE Linux Enterprise Server are registered trademarks of SUSE LLC. Madarson IT does not provide commercial licenses for SUSE products.
Highlights
Pre-Applied DISA STIG Controls for SUSE Linux Enterprise Server 16: This AMI ships with DISA STIG security controls already configured, including a DoD-standard login banner, immutable audit rules, hardened SSH settings, restricted services, and strict access controls. Your team can launch a compliant instance and focus on mission-specific configuration rather than spending days manually remediating hundreds of individual STIG findings before achieving Authority to Operate (ATO).
Multi-Framework Compliance Foundation: Pre-configured controls map to DISA STIGs for SUSE Linux Enterprise Server, NIST SP 800-53, FISMA, and Risk Management Framework (RMF) requirements. Organizations pursuing ATO can use this image as a validated baseline that addresses foundational OS-level controls across multiple federal frameworks simultaneously, reducing assessment scope and accelerating authorization timelines.
Continuously Updated and Maintained by Madarson IT: Madarson IT publishes hardened and custom images across AWS, GCP, and Azure Marketplace, with each image regularly updated to incorporate new STIG releases and security patches. This ensures your deployed instances stay aligned with current DISA guidance without requiring manual re-hardening after each benchmark update.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for this hardened SUSE Linux Enterprise Server 16 image, billed per running instance. Each dimension maps to a specific AWS EC2 instance type, so pricing scales with the compute size you choose. Smaller general-purpose and burstable instances (like t3 and t2 types) sit at one end, while larger compute-, memory-, storage-, and GPU-optimized instances (like c, m, r, d, i, g, and p families) cost more per hour. You select the instance that fits your workload, and hourly software charges apply on top of standard AWS infrastructure costs.
Top-of-mind questions for buyers
What does one hour of billing cover for this hardened SUSE Linux image?
One hour maps to one running EC2 instance of the type you select. Software charges meter per instance-hour of running time. If you run several instances, each accrues its own hourly charge. The rate matches the instance family and size you launch, layered on top of AWS infrastructure costs.
Am I charged the hourly software fee when an instance is stopped or paused?
The software fee meters running time only. A stopped or paused instance does not accrue hourly software charges. You may still pay underlying AWS storage costs for attached volumes while the instance is stopped. Charges resume once you start the instance again.
What do I get for choosing a larger instance type versus a smaller one?
The image and its DISA STIG hardening are the same across every instance type. Larger instances give more CPU, memory, storage, or GPU capacity, so you pick based on workload size. The hourly software charge rises with the instance size you select.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
SUSE Linux Enterprise Server 16 - Hardened for DISA STIG Compliance
Additional details
Usage instructions
Allow inbound SSH access in your security group (TCP port 22)
To connect to your instance using the Amazon EC2 console:
Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/.
In the navigation pane, choose Instances.
Select the instance and choose Connect.
Choose the EC2 Instance Connect tab.
For Connection type, choose Connect using EC2 Instance Connect.
Access the ec2 with the default username: "ec2-user"
Support
Vendor support
Contact Support
For questions about this DISA STIG-hardened image, private offers, compliance documentation, custom hardening requirements, or audit support, contact Madarson IT at info@madarsonit.com.
Support Scope
Madarson IT provides support for issues related to the STIG hardening configuration applied to this image, including guidance on interpreting scan results, understanding applied controls, and addressing configuration questions specific to the hardened baseline.
Getting Help
When contacting support, please include your AWS account ID, the AMI ID in use, and a description of the issue or request. This helps us respond efficiently and route your inquiry to the appropriate team member.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for security hardening.
Madarson IT DISA STIG-hardened SUSE Linux Enterprise Server 15 AMI for federal, DoD, and high-security AWS EC2 workloads requiring ATO readiness.
This product has charges associated with it for DISA STIG security hardening. Madarson IT's DISA STIG-hardened Red Hat Enterprise Linux 10 AMI for AWS EC2, pre-configured for federal and DoD security compliance in regulated cloud environments.
This product has charges associated with it for security hardening.
This AWS-based EC2 is pre-configured with the latest SUSE Linux Enterprise Server 16 image, hardened and optimized for security and compliance. Ready for production workloads.
This product has charges associated with it for DISA STIG security hardening. Madarson IT pre-hardened Ubuntu 24.04 LTS AMI with DISA STIG benchmarks applied. Deploy a compliance-ready EC2 instance for DoD and federal security requirements.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.