https://store-images.s-microsoft.com/image/apps.49436.2a5463aa-b7c9-45e1-b612-6cc5d3e93559.c869325d-2e30-466d-97c3-c06edbce80ea.c3a9c323-dd27-4fce-8727-3edb9d9c4dda

CIS Hardened Images on NGINX

Center For Internet Security, Inc. 

CIS Hardened Images on NGINX

Center For Internet Security, Inc. 

Hardened according to a CIS Benchmark - the consensus-based best practice for secure configuration.

A CIS Hardened Image is a pre-configured image built by the Center for Internet Security (CIS) for use on Azure Virtual Machines. It is built to offer an image secured to industry-recognized security guidance running on Azure Virtual Machines.

This image is pre-hardened to CIS Benchmarks guidance and patched monthly. CIS Hardened Images can be hardened to the Level 1, Level 2, or STIG profiles. No packages are installed on or removed from this image outside of those already present on the base image or as recommended in alignment with the corresponding CIS Benchmark recommendations.

The Level 1 profile is intended to be practical and prudent, provide a clear security benefit, and not inhibit the utility of the technology beyond acceptable means. The Level 2 profile is intended for environments or use cases where security is paramount, acts as a defense in depth measure, and may negatively inhibit the utility or performance of the technology. Guidance from the DoD Cloud Computing SRG indicates that CIS Benchmarks are an acceptable alternative in place of DISA STIGs - configuration standards for DoD Information Assurance (IA) and IA-enabled devices/systems. Launching an image that is hardened according to the CIS STIG Benchmark recommendations provides the ability to easily implement CIS guidance and DISA STIG at once.

To demonstrate conformance to the CIS Benchmark, industry-recognized hardening guidance, each image includes an HTML report from the CIS Configuration Assessment Tool (CIS-CAT Pro). Each CIS Hardened Image contains the following files:

  • Base_CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance before any change is made by CIS (e.g., software updates, CIS hardening).
  • basevm.txt - this provides a list of the packages resident on the instance prior to any change being made by CIS (e.g., software updates, CIS hardening).
  • CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance after the corresponding CIS Benchmark was applied to the image.
  • Exceptions.txt - this provides a list of recommendations that are not applied because configuration of those recommendations may inhibit use of this image in this CSP, require environment-specific expertise, or hinder integration of this image with CSP services or extensions.
  • afterhardening.txt - this provides a list of packages resident on the instance after the corresponding CIS Benchmark was applied to the image.

    These reports are located in /home/CIS_Hardened_Reports.

    To speak with us about additional pricing options and private offers, please contact us at cloudsecurity@cisecurity.org.

    To learn more or access the corresponding CIS Benchmark, please visit CIS Benchmarks™ or sign up for a free account on our community platform, CIS WorkBench, CIS WorkBench / Home.

  • https://store-images.s-microsoft.com/image/apps.16437.2a5463aa-b7c9-45e1-b612-6cc5d3e93559.c869325d-2e30-466d-97c3-c06edbce80ea.b5c15156-32e3-417a-80f6-62fd278a7d55
    /staticstorage/9fa6ec0/assets/videoOverlay_7299e00c2e43a32cf9fa.png
    https://store-images.s-microsoft.com/image/apps.16437.2a5463aa-b7c9-45e1-b612-6cc5d3e93559.c869325d-2e30-466d-97c3-c06edbce80ea.b5c15156-32e3-417a-80f6-62fd278a7d55
    /staticstorage/9fa6ec0/assets/videoOverlay_7299e00c2e43a32cf9fa.png
    https://store-images.s-microsoft.com/image/apps.31332.2a5463aa-b7c9-45e1-b612-6cc5d3e93559.c869325d-2e30-466d-97c3-c06edbce80ea.8a6512dd-6d91-42df-8154-5773fd15d6a1
    https://store-images.s-microsoft.com/image/apps.48469.2a5463aa-b7c9-45e1-b612-6cc5d3e93559.c869325d-2e30-466d-97c3-c06edbce80ea.5d23042e-ae3e-446d-8a72-87c9cac7bad9
    https://store-images.s-microsoft.com/image/apps.31065.2a5463aa-b7c9-45e1-b612-6cc5d3e93559.c869325d-2e30-466d-97c3-c06edbce80ea.1beb1017-18c0-44e1-a404-ca81ef163c7b