
Amazon WorkSpaces CIS compliant Windows image guidelines
This document provides prescriptive guidance for configuring Amazon WorkSpaces Windows images using the Center for Internet Security (CIS) Benchmarks security. standard.
What CIS Benchmarks Apply to Amazon Workspaces?
Applying CIS Benchmarks to Amazon Workspaces
Amazon Web Services Foundations Benchmark (v2.0.0)
Identity and Access Management
1.1.15 Ensure IAM Users Receive Permissions Only Through Groups
1.1.16 Ensure IAM policies that allow full “*:*” administrative privileges are not attached
1.1.18 Ensure IAM instance roles are used for AWS resources access from instances
2.2.2.1 Ensure EBS Volume Encryption is Enabled in All Regions
2.2.4.1 Ensure that encryption is enabled for EFS file systems
AWS End User Compute Services Benchmark (v1.0.0)
Microsoft Windows Server 2016, 2019 & 2022 Benchmark (v2.0.0)
Note about CIS Benchmarks for this section
2.2.4.6 Ensure 'Shut down the system' is set to 'Administrators'
Wired Network (IEEE 802.3) Policies
Windows Defender Firewall with Advanced Security
9.1.2 Ensure 'Windows Firewall: Domain: Inbound connections' is set to 'Block (default)'
9.2.2 Ensure 'Windows Firewall: Private: Inbound connections' is set to 'Block (default)'
9.3.2 Ensure 'Windows Firewall: Public: Inbound connections' is set to 'Block (default)'
Wireless Network (IEEE 802.11) Policies
Network Access Protection NAP Client Configuration
Advanced Audit Policy Configuration
Administrative Templates (Computer)
Administrative Templates (User)
Wired Network (IEEE 802.3) Policies
Windows Defender Firewall with Advanced Security
9.1.2 Ensure 'Windows Firewall: Domain: Inbound connections' is set to 'Block (default)'
9.2.2 Ensure 'Windows Firewall: Private: Inbound connections' is set to 'Block (default)'
9.3.2 Ensure 'Windows Firewall: Public: Inbound connections' is set to 'Block (default)'
Wireless Network (IEEE 802.11) Policies
Network Access Protection NAP Client Configuration
Advanced Audit Policy Configuration
Administrative Templates (Computer)
Administrative Templates (User)
Wired Network (IEEE 802.3) Policies
Windows Defender Firewall with Advanced Security
9.1.2 Ensure 'Windows Firewall: Domain: Inbound connections' is set to 'Block (default)'
9.2.2 Ensure 'Windows Firewall: Private: Inbound connections' is set to 'Block (default)'
9.3.3 Ensure 'Windows Firewall: Public: Inbound connections' is set to 'Block (default)'
Wireless Network (IEEE 802.11) Policies
Network Access Protection NAP Client Configuration
Advanced Audit Policy Configuration
Administrative Templates (Computer)
Administrative Templates (User)
Assessing and Maintaining CIS Benchmark Compliance
- Amazon Web Services Foundations Benchmark
- AWS End User Compute Services Benchmark
- Relevant OS Benchmark (e.g., Windows, Linux)
- Relevant application Benchmarks (e.g., web browsers, business applications)
- TCP / UDP 4172 (PCoIP)
- TCP / UDP 4195 (WSP)
- TCP / UDP 8200
- TCP 4489 (Web client)
- TCP 8201-8250 (Amazon DCV)
- TCP / UDP 4172 (PCoIP)
- TCP / UDP 4195 (WSP)
- TCP / UDP 8200
- TCP 4489 (Web client)
- TCP 8201-8250 (Amazon DCV)
- TCP / UDP 4172 (PCoIP)
- TCP / UDP 4195 (WSP)
- TCP / UDP 8200
- TCP 4489 (Web client)
- TCP 8201-8250 (Amazon DCV)
- TCP / UDP 4172 (PCoIP)
- TCP / UDP 4195 (WSP)
- TCP / UDP 8200
- TCP 4489 (Web client)
- TCP 8201-8250 (Amazon DCV)
- TCP / UDP 4172 (PCoIP)
- TCP / UDP 4195 (WSP)
- TCP / UDP 8200
- TCP 4489 (Web client)
- TCP 8201-8250 (Amazon DCV)
- TCP / UDP 4172 (PCoIP)
- TCP / UDP 4195 (WSP)
- TCP / UDP 8200
- TCP 4489 (Web client)
- TCP 8201-8250 (Amazon DCV)
- TCP / UDP 4172 (PCoIP)
- TCP / UDP 4195 (WSP)
- TCP / UDP 8200
- TCP 4489 (Web client)
- TCP 8201-8250 (Amazon DCV)
- TCP / UDP 4172 (PCoIP)
- TCP / UDP 4195 (WSP)
- TCP / UDP 8200
- TCP 4489 (Web client)
- TCP 8201-8250 (Amazon DCV)
- TCP / UDP 4172 (PCoIP)
- TCP / UDP 4195 (WSP)
- TCP / UDP 8200
- TCP 4489 (Web client)
- TCP 8201-8250 (Amazon DCV)
- Robert Fountain
- David Ryder
- Don Scott
- Michael Lamanna
- Michael Mattes
- Nicholas Czabaranek
- Puria Djafari
- Roger LaMarca
- Roy Tokeshi
Any opinions in this post are those of the individual author and may not reflect the opinions of AWS.