| name | cis-aws-compute-5.1 |
| description | Apply updates to any apps running in Lightsail |
| category | cis-compute |
| version | 1.1.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","compute","lightsail","patching","updates","applications"] |
| cis_id | 5.1 |
| cis_benchmark | CIS AWS Compute Services Benchmark v1.1.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-compute-5.11"] |
| prerequisites | [] |
| severity_boost | {} |
5.1 Apply updates to any apps running in Lightsail (Manual)
Description
Amazon Lightsail is a virtual private server (VPS) provider and is the easiest way to get started with AWS for developers, small businesses, students, and other users who need a solution to build and host their applications on cloud.
Rationale
Lightsail offers a range of operating system and application templates that are automatically installed when you create a new Lightsail instance. Application templates include WordPress, Drupal, Joomla!, Ghost, Magento, Redmine, LAMP, Nginx (LEMP), MEAN, Node.js, Django, and more. You can install additional software on your instances by using the in-browser SSH or your own SSH client.
Impact
N/A
Audit Procedure
Using AWS Console
To confirm that you are running the latest version of the application you are using is a manual process. Often dependent on the application itself and the operating system you are utilizing for the Lightsail instance.
- Login to AWS Console using https://console.aws.amazon.com
- Click
All services, click Lightsail under Compute.
- This will open up the Lightsail console.
- Select the
Instance you want to review.
- Make sure the instance status is
running.
- Connect to the
instance.
- Depending on the instance OS and the application you are running determine what version it is and if there are any updates.
- If there are updates refer to the remediation below.
- Repeat steps no. 4 - 8 to verify if any Lightsail instances require application updates.
Using AWS CLI
N/A - This is a manual process dependent on the application and OS.
Expected Result
All applications running on Lightsail instances should be running the latest stable version with all security patches applied.
Remediation
Using AWS Console
- Login to AWS Console using https://console.aws.amazon.com
- Click
All services, click Lightsail under Compute.
- This will open up the Lightsail console.
- Select the
Instance you want to update.
- Make sure the instance status is
running.
- Click on
Snapshots
- Under
Manual snapshots click on