Hacker News new | ask | show | jobs
by Geee 2682 days ago
Thanks. What about using the hardened images they provide? https://www.cisecurity.org/cis-hardened-image-list/
2 comments

Their hardened images are fine but there are two issues. First, you'll need to test / dev with them as full implementations of CIS can break things (though not as bad as the STIGs) and, IIRC, they charge extra for you to use their images on public clouds.
From what I can tell, their images are only for the big three cloud providers.