Ensure that your Amazon Machine Images (AMIs) can be used only by trusted (friendly) AWS accounts in order to prevent unauthorized users from getting access to sensitive information, as these AMIs can contain proprietary applications, personal data, and configuration information that can be used to exploit or compromise EC2 instances launched within your AWS cloud account. Before running this rule by the Trend Cloud One™ – Conformity engine, the list with the trusted AWS account identifiers must be configured in the rule settings, on your Conformity account console.
Allowing unknown cross-account access to your Amazon Machine Images (AMIs) can authorize untrusted AWS users to launch EC2 instances using your AMIs.
Audit
To determine if there are AMIs configured to allow unknown cross-account access available within your AWS account, perform the following actions:
Remediation / Resolution
To update your AMIs permissions in order to share your images with trusted AWS accounts only, perform the following actions:
References
- AWS Documentation
- Amazon Machine Images (AMI)
- Shared AMIs
- Share an AMI with specific AWS accounts
- AWS Command Line Interface (CLI) Documentation
- ec2
- describe-image-attribute
- describe-images
- modify-image-attribute