Low EC2 Regional

EC2 launch templates should use Instance Metadata Service Version 2 (IMDSv2)

PCI DSS v4.0.1PCI DSS v2.2.6

Description

Confirms that the default version of EC2 launch templates requires IMDSv2 for instance metadata access.


Remediation

To enable IMDSv2 for your EC2 launch templates, you need to set the HttpTokens parameter to 'required' in the metadata options of the default version of the launch template.

Steps

  1. Open the Amazon EC2 console
  2. Navigate to Launch Templates
  3. Select the launch template you want to modify and click on the default version
  4. In the Advanced details section, expand 'Metadata options'
  5. Set 'Metadata access' to 'Required (IMDSv2)'
  6. Save the changes to the launch template

Compliance

PCI DSS v4.0.1PCI DSS v2.2.6