top of page

EC2.8

EC2 instances should use Instance Metadata Service Version 2 (IMDSv2)

Severity

Cloud Platforms

Resources

Related Standards

Automated

HIGH

AWS

Amazon EC2

AWS Foundational Best Practice, NIST.800-53.r5,

This control checks whether your Amazon Elastic Compute Cloud (Amazon EC2) instance metadata version is configured with Instance Metadata Service Version 2 (IMDSv2). The control passes if HttpTokens is set to required for IMDSv2. The control fails if HttpTokens is set to optional.

bottom of page