As for whether they actually harden your servers, that's up for you to decide if you think that CIS actually helps. It certainly does reduce attack surface.
As for whether they actually harden your servers, that's up for you to decide if you think that CIS actually helps. It certainly does reduce attack surface.
Official Ubuntu cis docker images in AWS:
- change the sysctls which do not apply to containers
- install a file consistency checker, which likely makes no sense in a dedicated container
- install tcpwrappers which you'll probably never use... for compliance reasons
- adjust system user password policies which you're probably not using at all
Unless you need to tick some compliance boxes in the quickest and most silly way, go for CIS. If you don't, schedule some time with a security person at your company to create a real threat model and change the things that will make an impact.
I haven't run into any situations where container images need to have CIS benchmarks applied, only VMs.
"""The CIS Benchmarks® are prescriptive configuration recommendations for more than 25+ vendor product families. They represent the consensus-based effort of cybersecurity experts globally to help you protect your systems against threats more confidently."""