| name | cis-aws-euc-5.7 |
| description | Ensure Operating system updates are applied to your base image every 30 days |
| category | cis-end-user-compute |
| version | 1.2.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","end-user-compute","appstream","patch-management","image-management"] |
| cis_id | 5.7 |
| cis_benchmark | CIS AWS End User Compute Services Benchmark v1.2.0 |
| tech_stack | ["aws"] |
| cwe_ids | ["CWE-1357"] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Ensure Operating system updates are applied to your base image every 30 days (Manual)
Profile Applicability
Description
To ensure that your fleet instances have the latest Windows updates installed, we recommend that you install Windows updates on your image builder, create a new image, and then update your fleet with the new image once a month.
Rationale
All fleet instances used in user streaming sessions have only the Windows and application updates that were installed on the underlying image when it was created. In addition, any updates made to Windows or to applications on the instance during the streaming session will not persist to future sessions by the same user or other users.
Impact
None - this is a security best practice.
Audit Procedure
Perform the following steps to review the Image date.
Using AWS Console
- Log in to the AppStream 2.0 console at
https://console.aws.amazon.com/appstream2
- In the left pane click on Images
- Select the Image Builder tab
- Select the link for the Image builder name you wish to view
- In the Image builder details tab review the Created at date and the AppStream agent version
If the created at date is over 30 days old refer to the remediation below.
Using AWS CLI
Not applicable - must be audited via Console.
Expected Result
AppStream image builder is less than 30 days old.
Remediation
Using AWS Console
Perform the steps below to create an image and update it:
- Log in to the AppStream 2.0 console at
https://console.aws.amazon.com/appstream2
- Click Images in the left pane, then Click the Image Builder tab, and Click Launch Image Builder
- Choose a base image. The latest base images released by AWS is recommended and selected by default
- Click Next
- Configure Image Builder, by doing the following:
- Name: Type a unique name identifier for the image builder
- Display name (optional): Type a name to display for the image builder (maximum of 100 characters)
- Tags (optional): Choose Add Tag, and type the key and value for the tag. To add more tags, repeat this step