EC2 instances should be managed by SSM

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Description

This control verifies that EC2 instances in a running or stopped instance state are managed by AWS Systems Manager (SSM). SSM is a service designed to monitor, manage and patch your AWS infrastructure.

EC2 instances should be managed by SSM to enhance security, ensure compliance, and streamline management. SSM enables centralized control, automated monitoring, and remediation of policy violations, while simplifying configuration and maintenance of instances.

Remediation

For guidance on managing EC2 instances with SSM, refer to the Amazon EC2 host management section of the AWS Systems Manager User Guide.