Listing Thumbnail

    CIS Hardened Image Level 1 on Oracle Linux 8

     Info
    Deployed on AWS
    AWS Free Tier
    This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.

    Overview

    The CIS Hardened Image Level 1 on Oracle Linux 8 is a pre-configured image built by the Center for Internet Security (CIS®) for use on Amazon Elastic Compute Cloud (Amazon EC2). It is a pre-configured, security-hardened image that aligns with the robust security recommendations, the CIS Benchmarks, making it easier for organizations to meet regulatory requirements.

    Not only is this image pre-hardened to the CIS Benchmarks guidance, but it is also patched monthly in alignment with the updates from the software vendor.

    Key Benefits

  • Enhanced Security: Mitigates risks like malware, denial of service, and authorization issues by following globally-recognized secure configuration guidance to support your cloud security posture management (CSPM) program.
  • Compliance Readiness: Helps your organization comply with PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
  • Faster Deployment: Pre-configured according to CIS Benchmarks, allowing you to deploy secure virtual machine images.
  • Consistency Across Environments: Ensures consistent security configurations across development, testing, and production environments, reducing drift and compatibility risks.
  • Cost Efficiency: Lowers remediation efforts, reduces attack surface, and minimizes business loss from security incidents.
  • Easier Maintenance: Regular updates ensure that your systems are always in line with the latest security standards and software patches.

    This image is hardened against the corresponding Level 1 profile which is intended to be practical and prudent, provide a clear security benefit, and not inhibit the utility of the technology beyond acceptable means. No packages are installed on or removed from this image outside of those already present on the base image or as recommended in alignment with the corresponding CIS Benchmark recommendations.

    To demonstrate conformance to the CIS Oracle Linux 8 Level 1 Benchmark, industry-recognized hardening guidance, each image includes an HTML report from CIS Configuration Assessment Tool (CIS-CAT® Pro). Each CIS Hardened Image contains the following files:

  • Base_CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance before any change is made by CIS (e.g., software updates, CIS hardening).
  • basevm.txt - this provides a list of the packages resident on the instance prior to any change being made by CIS (e.g., software updates, CIS hardening).
  • CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance after the corresponding CIS Benchmark was applied to the image.
  • Exceptions.txt - this provides a list of recommendations that are not applied because the configuration of those recommendations may inhibit the use of this image in this CSP, require environment-specific expertise, or hinder the integration of this image with CSP services or extensions.
  • afterhardening.txt - this provides a list of packages resident on the instance after the corresponding CIS Benchmark was applied to the image.

    These reports are located in /home/CIS_Hardened_Reports.

    For customized pricing options or private offers, reach out to us at cloudsecurity@cisecurity.org .

    To learn more or access the corresponding CIS Benchmark, please visit https://www.cisecurity.org/cis-benchmarks  or sign up for a free account on our community platform, CIS WorkBench, https://workbench.cisecurity.org/ .

  • Highlights

    • Hardened according to a Level 1 CIS Benchmark that is developed in a consensus-based process and that is accepted by government, business, industry, and academia.
    • Helps with compliance to PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
    • Pre-configured to align with industry best practices that are developed and supported by CIS, this image has hardened account and local policies, firewall configuration, and computer-based and user-based administrative templates.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux 8

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    CIS Hardened Image Level 1 on Oracle Linux 8

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (632)

     Info
    • ...
    Dimension
    Cost/hour
    t3.medium
    Recommended
    $0.022
    t2.micro
    AWS Free Tier
    $0.02
    t3.micro
    AWS Free Tier
    $0.022
    m7a.8xlarge
    $0.05
    r5dn.xlarge
    $0.024
    g6.24xlarge
    $0.06
    m6in.12xlarge
    $0.055
    c6id.12xlarge
    $0.055
    g5.12xlarge
    $0.055
    t2.nano
    $0.02

    Vendor refund policy

    Refunds through AWS are not available at this time. You will only be billed for actual time of instance use. As with all CIS security products, our aim is always 100 percent customer/member satisfaction.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    NA

    Additional details

    Usage instructions

    Once the instance is running, connect using SSH. Use "ec2-user" as the username. Immediately apply latest security updates after launching the instance.

    Support

    Vendor support

    Questions, feedback, and support accessing CIS-developed AMIs is provided by contacting

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    25
    In Compliance and Auditing

    Overview

     Info
    AI generated from product descriptions
    Security Hardening
    Pre-configured image hardened according to CIS Benchmarks Level 1 profile with comprehensive security configurations
    Configuration Assessment
    Includes CIS Configuration Assessment Tool (CIS-CAT Pro) reports documenting pre and post-hardening system states
    Compliance Reporting
    Provides detailed HTML reports and text files documenting system packages and hardening exceptions
    Security Policy Management
    Implements hardened account policies, local policies, firewall configurations, and administrative templates
    Patch Management
    Monthly patched image aligned with software vendor updates to maintain current security standards
    Cryptographic Compliance
    FIPS 140-2 certified kernel and cryptographic modules with out-of-the-box compliance
    Security Patch Coverage
    Comprehensive security updates for over 23,000 open source packages across Ubuntu Universe repository
    Compliance Hardening
    Integrated hardening profiles from CIS and DISA-STIG security implementation guidelines
    Kernel Security
    FIPS-certified kernel with ongoing security updates for cryptographic components
    Security Tooling
    Ubuntu Security Guide (USG) for automated compliance and security configuration management
    Security Hardening
    "Configured with Security Technical Implementation Guides (STIG) Benchmark High to enhance system security posture"
    Operating System Compatibility
    "Optimized Amazon Linux 2 distribution configured for compatibility with Amazon Elastic MapReduce (EMR)"
    Compliance Standard
    "Meets Defense Information System Agency (DISA) configuration standards for system hardening"
    Security Configuration
    "Implements advanced security settings to improve overall system protection"
    Platform Optimization
    "Pre-configured Linux image with specialized security and performance configurations"

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    3.8
    2 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    50%
    50%
    0%
    0%
    2 AWS reviews
    |
    21 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    reviewer2774253

    Has improved server administration with secure configuration and stable repositories

    Reviewed on Nov 01, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Oracle Linux  is for administration, specifically full administration for Unix servers, such as hosting applications, monitoring the server health, and all the administration tasks I have been using it for.

    I am hosting applications on those servers and monitoring the servers that are operating on Oracle Linux  with full monitoring.

    What is most valuable?

    The best features Oracle Linux offers include security, as I have found it to be more secure than Ubuntu , Red Hat, and other Linux distributions. Additionally, it is easier to use than the other Linux operating systems.

    What makes Oracle Linux more secure and easier to use than other Linux operating systems I have tried is the configuration of the firewall, SSH, and a few other configurations. These are easy to follow and set up.

    I remember that the repositories for Oracle Linux are more stable than those of others. For instance, with Ubuntu , I have faced some issues related to the repository for the NFC files. The repositories of Oracle Linux are working smoothly more than others.

    Oracle Linux has positively impacted my organization as most servers we are using are Oracle Linux. We prefer using it. The reason my organization prefers Oracle Linux is for its performance and reliability. In general, the operating system is cleaner and easy to use and follow.

    What needs improvement?

    I have no suggestions for improvements regarding Oracle Linux. Everything is going well.

    For how long have I used the solution?

    I have been using Oracle Linux for three years.

    What do I think about the stability of the solution?

    Oracle Linux is stable.

    What do I think about the scalability of the solution?

    The scalability of Oracle Linux is working fine, and there are no issues we have faced regarding scalability.

    How are customer service and support?

    I have not interacted with Oracle's support team. All the cases we were solving were done by ourselves in the team.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    Before Oracle Linux, we were using Red Hat, but it was an old version.

    What was our ROI?

    I have not seen a return on investment with Oracle Linux.

    What's my experience with pricing, setup cost, and licensing?

    Our experience with pricing, setup cost, and licensing involved using VMware Cloud, and I have no idea about the cost.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Oracle Linux. This is the first time I am evaluating an operating system.

    What other advice do I have?

    I recommend using Oracle Linux as your first choice for Linux distributions. I have rated this review a 10.

    ArkaSarkar

    Has reduced operational time and supports critical daily functions with strong query performance

    Reviewed on Oct 31, 2025
    Review from a verified AWS customer

    What is our primary use case?

    Oracle Linux  is essential for my day-to-day operations, including reports collection, developing new queries to solve customer issues, charging support, and normal CSR cases, as well as any escalation. Oracle Linux  is everything in my domain.

    Common examples include organizational operations such as running mission-critical Oracle databases for business functions including enterprise resource planning (ERP), customer relationship management (CRM ), and data analytics. These are the main use cases I can identify. Ksplice as well as database host operations use Oracle Linux exclusively because our test servers and test charging system servers are already established in Oracle Linux.

    All of our test lab servers are deployed in Oracle Linux, and customer queries, customer data, and customer report collection are all dependent on Oracle Linux nowadays. Oracle Linux RHEL  compatibility is excellent for our use. The revenue impact has been significant, as our work has become considerably easier and time consumption has decreased substantially by using Oracle Linux. This directly correlates to revenue improvement as well.

    What is most valuable?

    The best features of Oracle Linux include the Unbreakable Enterprise Kernel for performance, zero-downtime patching, RHEL  compatibility with the latest RHEL versions, and paid support, which is optional. Oracle Linux support is excellent. Oracle Clusterware and DTrace tracing are also positive aspects of using Oracle Linux. It is free to use and distribute.

    Oracle Linux RHEL compatibility is exceptional because it is binary and source compatible with Red Hat Enterprise Linux , which ensures broad compatibility with existing applications. Deep integration is also an important key factor in using Oracle Linux.

    DTrace is a dynamic tracing framework that allows me to perform real-time analysis of the running system in my daily work to identify performance bottlenecks. This is an important example of Oracle Linux that I use both within my organization and outside of it.

    What needs improvement?

    Automatic patching and updates with features like Ksplice for zero-downtime patching and OS management for centralized management could be improved. Other partial improvements include enhancing security by using FIPS and Common Criteria certified distribution, as well as optimizing performance with KVM  virtualization. However, I believe that Oracle Linux is currently functioning fine with my use.

    When comparing industry trends, I want to add that there are different workloads such as Oracle Database  for implementing pre-installation packages, which can ensure all dependencies are met for a smoother installation process. These aspects could be improved, as well as streamlining of DevOps.

    For how long have I used the solution?

    I have been using Oracle Linux for the last four years.

    What do I think about the stability of the solution?

    Oracle Linux is stable. When connectivity issues occur, the support team is always available to provide support 24/7, which is a positive aspect.

    What do I think about the scalability of the solution?

    In terms of scalability, Oracle Linux performs well. I have already mentioned improvements such as downtime patching and OS management for centralized management. Beyond that, scalability is functioning well.

    How are customer service and support?

    Oracle Linux customer support is very active. They provide 24/7 support for both emergency and normal issues. They typically hold tickets for one or two days and provide effective solutions, which is a positive aspect.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I started from scratch using only Oracle Linux because I learned from others that it is very easy to use and is a very practical solution in the current industry.

    How was the initial setup?

    I did not conduct an evaluation.

    What about the implementation team?

    We purchased Oracle Linux from AWS . As I have already mentioned, time consumption decreased significantly and productivity is now strong, with revenue savings achieved.

    What was our ROI?

    From a customer satisfaction perspective, this is indeed important. Time consumption has decreased substantially. When compared to other relational databases, there is a 20 to 30 percent gap. By using Oracle Linux, I am obtaining a 20 to 30 percent advantage.

    What's my experience with pricing, setup cost, and licensing?

    We use both Google and AWS . The pricing is quite reasonable with no concerns.

    Which other solutions did I evaluate?

    All of our test lab servers are deployed in Oracle Linux, and customer queries, customer data, and customer report collection are all dependent on Oracle Linux nowadays. Oracle Linux RHEL compatibility is excellent for our use. The revenue impact has been significant, as our work has become considerably easier and time consumption has decreased substantially by using Oracle Linux. This directly correlates to revenue improvement.

    What other advice do I have?

    Oracle Linux is the best option in the current industry. I would recommend that anyone not currently using it conduct testing for at least six months to one year, and they will experience the difference and will never leave Oracle Linux after that. The overall review rating for Oracle Linux is 8.5 out of 10.
    Behal Karun

    Has reduced costs and simplified testing through open access to tools

    Reviewed on Oct 15, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I am using Oracle Linux  on a daily basis.

    My main use case for Oracle Linux  is that we have lots of applications.

    A specific example of how I'm using Oracle Linux is for the server and application server for company applications.

    My company uses Oracle Linux for application and monitoring purposes.

    What is most valuable?

    The best features Oracle Linux offers are that it's simple and easy to understand.

    The usefulness of these features comes from the fact that it is an open tool, allowing for free access to all applications on the web, enabling easy testing and checking of any new application features for testing purposes. This is the main feature in Oracle Linux.

    Oracle Linux features, such as being very easy to understand, allow for easy access to all repositories and packages available online, making it very helpful with no need to purchase any other packages or related subscriptions since it's totally free and easy to adopt.

    Oracle Linux has positively impacted my organization through cost saving.

    What needs improvement?

    Oracle Linux can be improved by adding more features related to Oracle Linux and including an AI assistant.

    They should provide Oracle Linux-related training videos free of cost so everyone can easily learn.

    For how long have I used the solution?

    I have been working in my current field for the last 18 years.

    What do I think about the stability of the solution?

    Oracle Linux is stable in my experience and has been reliable for my organization.

    What do I think about the scalability of the solution?

    The scalability of Oracle Linux is good and can handle growth and increased demand.

    How are customer service and support?

    When we have encountered issues, we have interacted with the support team and received solutions from them, indicating the customer support for Oracle Linux is satisfactory.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    Previously, we were using HP-UX before switching to Oracle Linux.

    What was our ROI?

    I have seen a return on investment with Oracle Linux in terms of time saved.

    What's my experience with pricing, setup cost, and licensing?

    I am not properly informed about the pricing, setup cost, and licensing for Oracle Linux because I'm not involved in that aspect of operations.

    Which other solutions did I evaluate?

    It is understandable and very easy to use Oracle Linux compared to other options I considered before choosing it.

    My advice to others looking into using Oracle Linux is that it is very easy and easily adaptable to any hardware. If you are choosing open-source applications, moving to the Linux environment makes Oracle Linux the best compared to Red Hat because Red Hat charges for satellite patching management while Oracle Linux offers a totally free repository to download and upgrade your Oracle without any cost.

    What other advice do I have?

    We use Azure  and OCI  as our cloud provider with Oracle Linux.

    Oracle Linux is deployed in my organization on-premises.

    My company has a business relationship with Oracle as a partner.

    I rate Oracle Linux 8 out of 10.

    Badhon Islam

    Has improved security and reduced downtime through built-in tools and a reliable kernel

    Reviewed on Sep 22, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Oracle Linux  at Deep System is that we are using it for big data.

    In my main use case for Oracle Linux , it's based on Red Hat, and it's secure, reliable, and open source.

    What is most valuable?

    In my experience, the best features Oracle Linux offers include its unbreakable kernel system and security, along with reliability and stability.

    The unbreakable kernel and the security features stand out for me because, in big data, anyone from outside cannot break my kernel, and we have a lot of inbuilt security, which has helped me with different things.

    Oracle Linux provides many more features that I need to consider further.

    Oracle Linux has positively impacted my organization because of its numerous features. It's a stable version that I use in an inter-cloud network, so I don't need to regularly update anything, and I don't need to expose my OS to the outside world, making this very positive.

    What needs improvement?

    Documentation for Oracle Linux is okay, and while user experience is good enough, it sometimes lags, so they can improve some areas there.

    Oracle Linux has many features, but it is sometimes heavy, and the response from my Oracle Linux is a little bit laggy. This may be because my kernel is lower at 5.14, which is why it's not so fast and sometimes creates lag or has a longer response time.

    For how long have I used the solution?

    I have been using Oracle Linux from the beginning of my job, which has been before 2024.

    What do I think about the stability of the solution?

    In my experience, Oracle Linux is approximately 95% stable.

    What do I think about the scalability of the solution?

    Oracle Linux's scalability is designed for big data, so it may be scalable, but it takes a lot of resources and has many big data issues.

    How are customer service and support?

    I actually don't need customer support for Oracle Linux at this time, but if I needed it, I would ask and share that experience.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    From the first day, we have been using Oracle Linux, but before that, we were using AlmaLinux  for our cPanel  hosting and CentOS  for other uses. We are not using CentOS  anymore because it is not updated.

    What was our ROI?

    Having used Oracle Linux, I can say money is saved because our server is working efficiently, and time is saved due to many inbuilt tools that help us since we are in the cloud network.

    In terms of outcomes or benefits I've seen over the last year, we have more than 30 servers, and we only need to reboot one server while all other servers continue working fine, resulting in very low downtime, which is very helpful.

    Which other solutions did I evaluate?

    Before choosing Oracle Linux, I evaluated options such as AlmaLinux  and Rocky Linux .

    What other advice do I have?

    My advice for others looking into using Oracle Linux is that it's good for Oracle Database , and it has its own open-source model along with a few things that are different from others. I rate Oracle Linux 8 out of 10.

    Charles Chinionga

    Has reduced downtime and improved performance while maintaining high security during database and web administration

    Reviewed on Sep 12, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Oracle Linux  is server administration, and I typically use it for web administration, application, and database administration in my work.

    A specific example of how I use Oracle Linux  with my databases is to implement our core banking system, where I use MySQL  and manage the database.

    Regarding how I use Oracle Linux, we are currently facing challenges with WebLogic, and we are using Apache and WebLog from Oracle that add to our tasks.

    What is most valuable?

    Oracle Linux helps with security and management in my bench system because we have many features that we can use to implement security, such as the firewall, which we configure, and it also helps when someone has to access our resource or database, especially concerning cybersecurity.

    The best features Oracle Linux offers for my organization stand out significantly in terms of security, particularly the firewall. The firewall in Oracle Linux helps my organization because it is reliable, offers ease of configuration, and is dependable to use.

    Oracle Linux provides fast updates, and the best aspect is that we can update our server without interrupting our service, which is very important for business continuity. When we moved to Oracle Linux, we noticed more performance in our applications, making our business operations smoother.

    Oracle Linux has impacted my organization positively by helping us reduce downtime, improving our performance, making our applications quicker, and increasing our security; we can fix problems easily with Oracle Linux.

    What needs improvement?

    I believe Oracle Linux could be improved, but I am very happy with it as it is.

    For how long have I used the solution?

    I have been using Oracle Linux for around eight years.

    What do I think about the stability of the solution?

    Oracle Linux is stable for my organization.

    What do I think about the scalability of the solution?

    Oracle Linux's scalability is excellent for our needs because our organization uses it for everything to achieve our goals.

    How are customer service and support?

    I have not had any recent experiences with the Oracle Linux support team; we are not currently using customer support, although I had an experience five years ago.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    Before Oracle Linux, we used a different solution, and we switched because Oracle Linux improved our performance and helped us reduce downtime significantly.

    What was our ROI?

    To measure these improvements, I track cost savings and user satisfaction, both of which are essential metrics for us.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for Oracle Linux has been that it is expensive.

    What other advice do I have?

    My advice to others looking into using Oracle Linux is that if they are seeking performance, security, and reliability, Oracle Linux is the best option for any business.

    I rate Oracle Linux 9 out of 10.

    View all reviews