Listing Thumbnail

    Madarson IT - DISA STIG Hardened Red Hat Enterprise Linux 8 AMI

     Info
    Sold by: Madarson IT 
    Deployed on AWS
    This product has charges associated with it for DISA STIG security hardening. Madarson IT pre-hardened RHEL 8 AMI with DISA STIG controls applied out of the box, helping federal and DoD teams accelerate Authority to Operate compliance.

    Overview

    Open image

    This is a repackaged software product wherein additional charges apply for DISA STIG security hardening.

    Madarson IT - DISA STIG Hardened Red Hat Enterprise Linux 8 AMI

    Deploy a pre-hardened RHEL 8 image built specifically for organizations that require DISA STIG compliance. This AMI eliminates weeks of manual hardening by delivering a security-optimized Red Hat Enterprise Linux 8 environment ready for production workloads in AWS.

    What You Get Out of the Box

    • RHEL 8 image with DISA STIG security controls pre-applied
    • Hardening aligned to the latest DISA STIG benchmark for Red Hat Enterprise Linux 8
    • Security configuration designed to address CAT I, CAT II, and CAT III findings
    • Image optimized to reduce vulnerabilities and help prevent unauthorized access
    • Built to support compliance validation using SCAP scanning tools

    Deployment Scenario

    A defense contractor deploying Controlled Unclassified Information (CUI) workloads in AWS can launch this AMI to establish a STIG-compliant baseline. Instead of spending weeks manually applying and validating hundreds of STIG controls, teams launch the pre-hardened image, run an OpenSCAP validation scan, document any residual findings requiring site-specific remediation, and include the results in their Authority to Operate (ATO) package for eMASS submission.

    Key Benefits

    Accelerate Time to Compliance Manual STIG hardening of a RHEL 8 system can take days or weeks. This AMI delivers pre-applied controls so your team can focus on mission workloads rather than baseline configuration.

    Reduce Risk of Misconfiguration STIG controls are applied systematically following DISA guidance, reducing the human error risk that comes with manual hardening across hundreds of individual settings.

    Support ATO and Audit Readiness Organizations maintaining Authority to Operate can use this image as a compliant foundation, then validate with SCAP-compatible scanning tools to generate audit-ready documentation.

    Consistent Security Posture Every instance launched from this AMI starts with the same hardened baseline, ensuring consistency across your fleet whether you deploy one instance or hundreds.

    Getting Started

    1. Subscribe to the product through AWS Marketplace
    2. Launch the AMI in your target VPC using a supported EC2 instance type
    3. Connect via SSH using your configured key pair
    4. Run a SCAP compliance scan to validate the hardening baseline
    5. Document any residual findings that require site-specific configuration
    6. Deploy your workload on the hardened foundation

    Who This Is For

    • DoD contractors and subcontractors requiring STIG-compliant infrastructure
    • Federal agencies maintaining Authority to Operate (ATO)
    • Organizations subject to FISMA compliance requirements
    • Security teams needing a hardened RHEL 8 baseline for sensitive workloads
    • FedRAMP-aligned SaaS vendors building on compliant infrastructure

    Why Madarson IT

    Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Our hardening process applies DISA STIG controls systematically to deliver a validated, production-ready image that saves your team significant time and effort.

    Madarson IT also offers hardened and custom images across AWS, GCP, and Azure Marketplace, covering multiple operating systems and compliance frameworks.

    Requirements and Limitations

    • This is a repackaged software product with additional charges for DISA STIG security hardening.
    • Buyers should verify compatibility with their target EC2 instance types before deploying at scale.
    • Application-layer STIGs and any CAT I findings requiring manual action remain the buyer's responsibility.
    • DISA STIG compliance requires more than technical controls at the operating system layer. Customers remain responsible for organizational, procedural, and additional infrastructure controls.
    • Buyers should run their own SCAP scan post-launch to validate compliance in their specific environment and document results for their accreditation package.

    About Madarson IT

    Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Our DISA STIG-hardened images help organizations meet federal cybersecurity requirements efficiently and reliably.

    Disclaimer

    Red Hat, Inc. holds the trademarks for Red Hat Enterprise Linux (RHEL) and associated branding. Madarson IT does not provide commercial licenses for Red Hat products.

    Highlights

    • Pre-Applied DISA STIG Controls: This AMI ships with DISA STIG security controls already applied to the RHEL 8 baseline, addressing CAT I, CAT II, and CAT III findings. Instead of spending days or weeks manually configuring hundreds of individual security settings, your team launches a hardened instance ready for compliance validation. Run a SCAP scan post-launch to verify the baseline and document any residual findings requiring site-specific remediation for your ATO package.
    • Audit-Ready Compliance Foundation: Built to support organizations maintaining Authority to Operate (ATO) under DoD, FISMA, and FedRAMP requirements. The systematic hardening process ensures every instance starts from an identical, validated security baseline - eliminating configuration drift and providing consistent audit evidence across your fleet. Use SCAP-compatible scanning tools to generate compliance documentation suitable for eMASS submission or inspector review.
    • Production-Ready With Regular Updates: Madarson IT maintains this image to reflect current DISA STIG guidance for Red Hat Enterprise Linux 8. The AMI is built to work out of the box on AWS EC2, reducing deployment friction for teams that need compliant infrastructure without building hardening automation from scratch. Each image release incorporates the latest applicable security controls so your baseline stays current with evolving DISA requirements.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Rhel 8.10

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Madarson IT - DISA STIG Hardened Red Hat Enterprise Linux 8 AMI

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (96)

     Info
    • ...
    Dimension
    Cost/hour
    m5.large
    Recommended
    $0.05
    m1.large
    $0.05
    m5.4xlarge
    $0.40
    m4.4xlarge
    $0.40
    h1.2xlarge
    $0.20
    r5.large
    $0.05
    r5.8xlarge
    $0.80
    i2.2xlarge
    $0.20
    r3.xlarge
    $0.10
    p3.8xlarge
    $0.80

    AI Insights

     Info

    Dimensions summary

    You pay by the hour for the same DISA STIG hardened Red Hat Enterprise Linux 8 image. Price varies only by the EC2 instance type you choose, not by software features. The dimensions map to AWS instance families and sizes. General purpose (m, t), compute optimized (c), memory optimized (r, i), storage optimized (d), and GPU/accelerated types (p, g, h) are all covered. Within each family, hourly cost rises as the instance size grows. You match the instance to your workload's compute, memory, or GPU needs and pay only for hours used.

    Top-of-mind questions for buyers

    The hourly rate covers the DISA STIG hardened Red Hat Enterprise Linux 8 software running on your chosen EC2 instance. You pick the instance family and size to match your compute, memory, storage, or GPU needs. The underlying AWS compute charges are billed separately by AWS.
    The software fee meters running instance-hours. A fully stopped instance does not accrue the hourly software charge. You may still owe AWS for attached storage while the instance is stopped, but the software licence bills only for the hours the instance runs.
    Every instance type runs the same hardened Red Hat Enterprise Linux 8 image with the same compliance configuration. Larger sizes give you more compute, memory, storage, or GPU capacity, not added software features. Hourly cost rises with size because the underlying resources grow, not the software.
    madarsonit.com
    Helpful?

    Vendor refund policy

    There is no refund policy for this image.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Hardened Red Hat Enterprise Linux 8 image with DISA STIG Benchmarks.

    Additional details

    Usage instructions

    Allow inbound SSH access in your security group (TCP port 22) To connect to your instance using the Amazon EC2 console: Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/ .

    In the navigation pane, choose Instances.

    Select the instance and choose Connect. Choose the EC2 Instance Connect tab. For Connection type, choose Connect using EC2 Instance Connect. Access the ec2 with the default username: "ec2-user"

    Support

    Vendor support

    Contacting Madarson IT Support

    For questions about this DISA STIG-hardened RHEL 8 AMI, including technical issues, compliance inquiries, private offers, or audit support, contact Madarson IT at info@madarsonit.com .

    What We Can Help With

    • Technical questions about the hardening configuration applied to the image
    • Guidance on post-launch compliance validation and SCAP scanning
    • Private offer requests for volume deployments or enterprise agreements
    • Audit and compliance consultation for DISA STIG, FISMA, or ATO requirements
    • Troubleshooting issues related to the hardened image configuration

    Getting Started After Purchase

    Once subscribed, launch the AMI in your target AWS region using a supported EC2 instance type. Connect via SSH using your configured key pair. The image is pre-hardened with DISA STIG controls applied. We recommend running a SCAP compliance scan after launch to validate the baseline and identify any site-specific configurations needed for your environment.

    For private offers, bulk licensing, or compliance consultation, please reach out to info@madarsonit.com  with your requirements.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.