This product has charges associated with it for DISA STIG security hardening. Madarson IT pre-hardened RHEL 8 AMI with DISA STIG controls applied out of the box, helping federal and DoD teams accelerate Authority to Operate compliance.
This is a repackaged software product wherein additional charges apply for DISA STIG security hardening.
Madarson IT - DISA STIG Hardened Red Hat Enterprise Linux 8 AMI
Deploy a pre-hardened RHEL 8 image built specifically for organizations that require DISA STIG compliance. This AMI eliminates weeks of manual hardening by delivering a security-optimized Red Hat Enterprise Linux 8 environment ready for production workloads in AWS.
What You Get Out of the Box
RHEL 8 image with DISA STIG security controls pre-applied
Hardening aligned to the latest DISA STIG benchmark for Red Hat Enterprise Linux 8
Security configuration designed to address CAT I, CAT II, and CAT III findings
Image optimized to reduce vulnerabilities and help prevent unauthorized access
Built to support compliance validation using SCAP scanning tools
Deployment Scenario
A defense contractor deploying Controlled Unclassified Information (CUI) workloads in AWS can launch this AMI to establish a STIG-compliant baseline. Instead of spending weeks manually applying and validating hundreds of STIG controls, teams launch the pre-hardened image, run an OpenSCAP validation scan, document any residual findings requiring site-specific remediation, and include the results in their Authority to Operate (ATO) package for eMASS submission.
Key Benefits
Accelerate Time to Compliance
Manual STIG hardening of a RHEL 8 system can take days or weeks. This AMI delivers pre-applied controls so your team can focus on mission workloads rather than baseline configuration.
Reduce Risk of Misconfiguration
STIG controls are applied systematically following DISA guidance, reducing the human error risk that comes with manual hardening across hundreds of individual settings.
Support ATO and Audit Readiness
Organizations maintaining Authority to Operate can use this image as a compliant foundation, then validate with SCAP-compatible scanning tools to generate audit-ready documentation.
Consistent Security Posture
Every instance launched from this AMI starts with the same hardened baseline, ensuring consistency across your fleet whether you deploy one instance or hundreds.
Getting Started
Subscribe to the product through AWS Marketplace
Launch the AMI in your target VPC using a supported EC2 instance type
Connect via SSH using your configured key pair
Run a SCAP compliance scan to validate the hardening baseline
Document any residual findings that require site-specific configuration
Deploy your workload on the hardened foundation
Who This Is For
DoD contractors and subcontractors requiring STIG-compliant infrastructure
Federal agencies maintaining Authority to Operate (ATO)
Organizations subject to FISMA compliance requirements
Security teams needing a hardened RHEL 8 baseline for sensitive workloads
FedRAMP-aligned SaaS vendors building on compliant infrastructure
Why Madarson IT
Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Our hardening process applies DISA STIG controls systematically to deliver a validated, production-ready image that saves your team significant time and effort.
Madarson IT also offers hardened and custom images across AWS, GCP, and Azure Marketplace, covering multiple operating systems and compliance frameworks.
Requirements and Limitations
This is a repackaged software product with additional charges for DISA STIG security hardening.
Buyers should verify compatibility with their target EC2 instance types before deploying at scale.
Application-layer STIGs and any CAT I findings requiring manual action remain the buyer's responsibility.
DISA STIG compliance requires more than technical controls at the operating system layer. Customers remain responsible for organizational, procedural, and additional infrastructure controls.
Buyers should run their own SCAP scan post-launch to validate compliance in their specific environment and document results for their accreditation package.
About Madarson IT
Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Our DISA STIG-hardened images help organizations meet federal cybersecurity requirements efficiently and reliably.
Disclaimer
Red Hat, Inc. holds the trademarks for Red Hat Enterprise Linux (RHEL) and associated branding. Madarson IT does not provide commercial licenses for Red Hat products.
Highlights
Pre-Applied DISA STIG Controls: This AMI ships with DISA STIG security controls already applied to the RHEL 8 baseline, addressing CAT I, CAT II, and CAT III findings. Instead of spending days or weeks manually configuring hundreds of individual security settings, your team launches a hardened instance ready for compliance validation. Run a SCAP scan post-launch to verify the baseline and document any residual findings requiring site-specific remediation for your ATO package.
Audit-Ready Compliance Foundation: Built to support organizations maintaining Authority to Operate (ATO) under DoD, FISMA, and FedRAMP requirements. The systematic hardening process ensures every instance starts from an identical, validated security baseline - eliminating configuration drift and providing consistent audit evidence across your fleet. Use SCAP-compatible scanning tools to generate compliance documentation suitable for eMASS submission or inspector review.
Production-Ready With Regular Updates: Madarson IT maintains this image to reflect current DISA STIG guidance for Red Hat Enterprise Linux 8. The AMI is built to work out of the box on AWS EC2, reducing deployment friction for teams that need compliant infrastructure without building hardening automation from scratch. Each image release incorporates the latest applicable security controls so your baseline stays current with evolving DISA requirements.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for the same DISA STIG hardened Red Hat Enterprise Linux 8 image. Price varies only by the EC2 instance type you choose, not by software features. The dimensions map to AWS instance families and sizes. General purpose (m, t), compute optimized (c), memory optimized (r, i), storage optimized (d), and GPU/accelerated types (p, g, h) are all covered. Within each family, hourly cost rises as the instance size grows. You match the instance to your workload's compute, memory, or GPU needs and pay only for hours used.
Top-of-mind questions for buyers
What does the hourly rate cover for each instance type I choose?
The hourly rate covers the DISA STIG hardened Red Hat Enterprise Linux 8 software running on your chosen EC2 instance. You pick the instance family and size to match your compute, memory, storage, or GPU needs. The underlying AWS compute charges are billed separately by AWS.
Am I charged the software fee when my instance is stopped or paused?
The software fee meters running instance-hours. A fully stopped instance does not accrue the hourly software charge. You may still owe AWS for attached storage while the instance is stopped, but the software licence bills only for the hours the instance runs.
Do larger instance sizes include extra software features or just more hardware?
Every instance type runs the same hardened Red Hat Enterprise Linux 8 image with the same compliance configuration. Larger sizes give you more compute, memory, storage, or GPU capacity, not added software features. Hourly cost rises with size because the underlying resources grow, not the software.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Hardened Red Hat Enterprise Linux 8 image with DISA STIG Benchmarks.
Additional details
Usage instructions
Allow inbound SSH access in your security group (TCP port 22)
To connect to your instance using the Amazon EC2 console:
Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/.
In the navigation pane, choose Instances.
Select the instance and choose Connect.
Choose the EC2 Instance Connect tab.
For Connection type, choose Connect using EC2 Instance Connect.
Access the ec2 with the default username: "ec2-user"
For questions about this DISA STIG-hardened RHEL 8 AMI, including technical issues, compliance inquiries, private offers, or audit support, contact Madarson IT at info@madarsonit.com.
What We Can Help With
Technical questions about the hardening configuration applied to the image
Guidance on post-launch compliance validation and SCAP scanning
Private offer requests for volume deployments or enterprise agreements
Audit and compliance consultation for DISA STIG, FISMA, or ATO requirements
Troubleshooting issues related to the hardened image configuration
Getting Started After Purchase
Once subscribed, launch the AMI in your target AWS region using a supported EC2 instance type. Connect via SSH using your configured key pair. The image is pre-hardened with DISA STIG controls applied. We recommend running a SCAP compliance scan after launch to validate the baseline and identify any site-specific configurations needed for your environment.
For private offers, bulk licensing, or compliance consultation, please reach out to info@madarsonit.com with your requirements.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for DISA STIG security hardening. Madarson IT pre-hardened RHEL 9 AMI for DISA STIG compliance. Launch a security-optimized EC2 instance ready for DoD and federal workloads out of the box.
This product has charges associated with it for DISA STIG security hardening. Madarson IT's DISA STIG-hardened Red Hat Enterprise Linux 10 AMI for AWS EC2, pre-configured for federal and DoD security compliance in regulated cloud environments.
This product has charges for security hardening. Madarson IT advanced hardened RHEL 8 AMI with pre-applied controls aligned to NIST CSF, ISO 27001, HIPAA, and PCI DSS.
This product has charges associated with it for PCI DSS security hardening. Pre-hardened RHEL 8 AMI by Madarson IT with PCI DSS security benchmarks applied out of the box, ready for organizations handling payment card data.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.