69 AWS listings · 8 Linux families · x86_64 + ARM64Open the live index ↗

HARDENING MODEL

Know what changes before your workload arrives.

Hardened Images applies operating-system security configuration before delivery, identifies the resulting artifact, and gives technical teams a concrete image to test in their own environment.

01

Source

Begin with the named upstream Linux distribution and major release.

02

Configure

Apply the security-focused operating-system changes associated with the product profile.

03

Identify

Publish the product line, operating system, release, architecture, and direct marketplace destination.

04

Evaluate

Give customer teams a concrete artifact to test with their application, automation, and operating model.

CONTROL REFERENCES

Keep program scope attached to the image layer.

Hardened Images supports teams using the following defense, governance, and cybersecurity programs. Standard Defense coverage includes Levels 1, 2, and 3; Foundation coverage includes Levels 1 and 2.

Program support is not a claim that every image or complete customer system is certified. Confirm product-specific alignment, control scope, version, evidence, exceptions, and compensating controls before use.

What the image configuration can change.

Hardening is valuable precisely because it changes insecure or permissive defaults.

Identity & access

Password policy, account behavior, privilege boundaries, and authentication settings.

Services & protocols

Unused services, legacy protocols, listening behavior, and network-facing defaults.

System policy

Permissions, audit configuration, kernel parameters, session behavior, and logging.

Packages & updates

Security updates and package configuration appropriate to the published image.

The artifact boundary, stated plainly.

Hardened Images publishes one important layer. The surrounding system remains yours to design and operate.

INSIDE THE HARDENED IMAGES ARTIFACT
  • Published image configuration
  • Image-specific product information
  • Current AWS listing destination
  • Seller support for product behavior
OUTSIDE THE HARDENED IMAGES ARTIFACT
  • Application compatibility and changes
  • Identity, networking, data, and secrets
  • Monitoring, vulnerability management, and response
  • Procedures, evidence, compliance, and authorization

Plan to pressure-test the image.

Secure defaults can reveal assumptions in an application stack. Run representative workloads, inspect every integration, and document accepted exceptions before production.

Review image support

Choose an image state to evaluate.

Search the current catalog by operating system, product line, and architecture.