FOUNDATION SECURITY

CAPABILITIES

Make the baseline deployable.

CAP / 01

Operating-system hardening

Configurations designed to reduce unnecessary exposure and establish a more secure default before application deployment.

CAP / 02

Framework alignment

A starting point informed by DISA STIG and NIST expectations, with scope confirmed at the individual product level.

CAP / 03

Cloud delivery

Images made available through cloud distribution and marketplace workflows for supported platforms.

CAP / 04

Repeatable launches

A consistent infrastructure starting state that can fit within your own image validation and promotion process.

CAP / 05

Application testing

Clear acknowledgment that hardened defaults can affect workloads—and should be tested before production.

CAP / 06

Technical support

A direct support path for questions about product launch, configuration behavior, and marketplace access.

SECURITY + COMPLIANCE FOCUS

Ten frameworks. One operating-system foundation.

Foundation focuses on infrastructure that can support federal, defense, public-safety, and regulated-system requirements. Alignment depends on the specific product and system boundary.

DISA STIG

Secure configuration baselines for Department of Defense information systems.

NIST SP 800-53 Rev. 5

Federal security and privacy control families for information systems and organizations.

NIST SP 800-171 Rev. 3

Requirements for protecting controlled unclassified information in nonfederal systems.

CMMC 2.0

Defense industrial base assessment expectations for safeguarding federal contract information and CUI.

FedRAMP Rev. 5

Cloud authorization control baselines derived from NIST SP 800-53 Revision 5.

FIPS 140-3 readiness

Readiness considerations for cryptographic-module requirements within the broader system boundary.

FBI CJIS 6.1

Security policy considerations for systems that process criminal justice information.

CISA CPGs

Cross-sector cybersecurity performance goals for reducing common and consequential risks.

NIST CSF 2.0

Governance and risk-management outcomes across identify, protect, detect, respond, and recover functions.

NIAP OSPP

Operating System Protection Profile considerations for evaluated general-purpose operating systems.

Framework focus does not mean that every product is certified, validated, authorized, or fully aligned to every listed framework. Confirm the exact baseline, version, cryptographic modules, evidence, and scope in the applicable product documentation and marketplace listing.

The boundary matters.

A hardened virtual machine addresses a defined part of the system: the operating-system layer and the configurations delivered with that image. That narrower scope is useful because it is testable.

Foundation provides

  • A hardened operating-system starting point
  • Cloud-ready virtual machine delivery
  • Product-specific configuration and support context

Your organization retains

  • System architecture, identity, networking, and data protection
  • Application security and workload compatibility
  • Logging, monitoring, procedures, evidence, and authorization