Operating-system hardening
Configurations designed to reduce unnecessary exposure and establish a more secure default before application deployment.
CAPABILITIES
Configurations designed to reduce unnecessary exposure and establish a more secure default before application deployment.
A starting point informed by DISA STIG and NIST expectations, with scope confirmed at the individual product level.
Images made available through cloud distribution and marketplace workflows for supported platforms.
A consistent infrastructure starting state that can fit within your own image validation and promotion process.
Clear acknowledgment that hardened defaults can affect workloads—and should be tested before production.
A direct support path for questions about product launch, configuration behavior, and marketplace access.
SECURITY + COMPLIANCE FOCUS
Foundation focuses on infrastructure that can support federal, defense, public-safety, and regulated-system requirements. Alignment depends on the specific product and system boundary.
Secure configuration baselines for Department of Defense information systems.
Federal security and privacy control families for information systems and organizations.
Requirements for protecting controlled unclassified information in nonfederal systems.
Defense industrial base assessment expectations for safeguarding federal contract information and CUI.
Cloud authorization control baselines derived from NIST SP 800-53 Revision 5.
Readiness considerations for cryptographic-module requirements within the broader system boundary.
Security policy considerations for systems that process criminal justice information.
Cross-sector cybersecurity performance goals for reducing common and consequential risks.
Governance and risk-management outcomes across identify, protect, detect, respond, and recover functions.
Operating System Protection Profile considerations for evaluated general-purpose operating systems.
Framework focus does not mean that every product is certified, validated, authorized, or fully aligned to every listed framework. Confirm the exact baseline, version, cryptographic modules, evidence, and scope in the applicable product documentation and marketplace listing.
A hardened virtual machine addresses a defined part of the system: the operating-system layer and the configurations delivered with that image. That narrower scope is useful because it is testable.