More Info:

Your AMI age should be more than configured number of days. This ensures that your EC2 instances deployed are secure and reliable.

Risk Level

Low

Address

Operational Maturity, Security, Reliability

Compliance Standards

HITRUST, SOC2, NISTCSF, FedRAMP

Triage and Remediation

Remediation

The AMI age should not exceed the configured age is a common misconfiguration in AWS. You can remediate this issue by following the below steps:

  1. Log in to your AWS Management Console.
  2. Go to the EC2 Dashboard.
  3. Click on the “AMIs” option from the left-hand navigation panel.
  4. Identify the AMI which has exceeded the configured age.
  5. Select the AMI and click on the “Actions” button.
  6. Choose the “Deregister” option from the drop-down list.
  7. Confirm the deregistration by clicking on the “Deregister” button in the confirmation dialog box.
  8. Once the AMI is deregistered, you can create a new AMI with the latest updates and configurations.

By following these steps, you can remediate the AMI age misconfiguration in AWS.

Additional Reading: