aws / aws/containers-roadmap

[FARGATE] [STIG]: Please Provide CKL File for STIGs That Apply to AMIs

Open
#2,030 0 comments 2 reactions 0 assignees View on GitHub
Fargate Proposed
Dominant language
Shell
Stars
5.4k
Forks
334
PR merge metrics
No merged PRs in 30d

Description

### Community Note

* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment

**Tell us about your request**
I would like to request documentation for STIGs that apply to AMIs. This was previously provided as a link to a spreadsheet, which was last verified by me on February 15, 2023. The document can be viewed using the Wayback Machine in a November archive:
https://web.archive.org/web/20221111144331/https://docs.aws.amazon.com/systems-manager-automation-runbooks/latest/userguide/awsec2-configurestig.html

However, this link has been removed from the current version of the site:
https://docs.aws.amazon.com/systems-manager-automation-runbooks/latest/userguide/awsec2-configurestig.html#ec2-linux-os-stig

The original link still works, but without the site referencing the information, it brings into question the validity and applicability of the spreadsheet:
https://aws-windows-downloads-us-west-1.s3.us-west-1.amazonaws.com/STIG/Linux+STIG.xlsx

**Which service(s) is this request for?**
This request pertains to Fargate, ECS, EKS, and EC2.

**Tell us about the problem you're trying to solve. What are you trying to do, and why is it difficult?**
I am trying to secure my container/application to be DISA-STIG compliant and need to know the HOST compliance status for elements such as cryptographic implementations and PRNG being NIST compliant for session IDs and hashing functions. This has become a challenge because containers utilize the HOST kernel, which needs to be FIPS certified.

**Are you currently working around this issue?**
This issue is currently blocking my container/application certification. I would not recommend other users requiring DISA-STIG certification to use these services until this issue is resolved.

**Additional context**
Documentation for DISA-STIG status for Fargate is required. There isn't anything directly under the Fargate documentation, which necessitates justification for looking at other instances such as EC2.

**Attachments**
N/A

Contributor guide

Open the contributing guide

Research direction

Start by comparing the current AWS Systems Manager Configure STIG documentation with the November Wayback archive and the linked Linux STIG.xlsx spreadsheet. Determine which STIG information applies to Fargate, ECS, EKS, and EC2, then document the applicable status and provide or link the requested CKL file. Done means the current AWS documentation clearly references the validated information.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud, documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.