Hardened baselines
Operating-system configurations aligned to recognized security guidance before a workload reaches production.
FEDERAL · DEFENSE · GOVERNMENT
DISA STIG and NIST-aligned infrastructure for government teams that need a hardened operating-system baseline before the mission begins.
NOTABLE ORGANIZATIONS
Foundation supports security-conscious teams across government, defense, and the enterprise partners that serve them.
Organization names and marks identify notable Foundation users. They do not imply endorsement, sponsorship, partnership, or government approval of Foundation Security.
THE FOUNDATION PRINCIPLE
Foundation gives public-sector teams a maintained starting point for the operating-system layer, reducing repetitive baseline work while leaving system ownership and authorization decisions where they belong.
CAPABILITIES
Foundation translates security guidance into cloud infrastructure that can be evaluated, tested, and launched through established workflows.
Operating-system configurations aligned to recognized security guidance before a workload reaches production.
A defined starting point for teams working across DISA STIG, NIST, CMMC, FedRAMP, CJIS, and related requirements.
Virtual machine products distributed through current AWS and Azure Marketplace destinations.
Human assistance for product launch, marketplace access, and configuration behavior.
SECURITY + COMPLIANCE FOCUS
Foundation focuses on infrastructure that can support federal, defense, public-safety, and regulated-system requirements. Alignment depends on the specific product and system boundary.
Secure configuration baselines for Department of Defense information systems.
Federal security and privacy control families for information systems and organizations.
Requirements for protecting controlled unclassified information in nonfederal systems.
Defense industrial base assessment expectations for safeguarding federal contract information and CUI.
Cloud authorization control baselines derived from NIST SP 800-53 Revision 5.
Readiness considerations for cryptographic-module requirements within the broader system boundary.
Security policy considerations for systems that process criminal justice information.
Cross-sector cybersecurity performance goals for reducing common and consequential risks.
Governance and risk-management outcomes across identify, protect, detect, respond, and recover functions.
Operating System Protection Profile considerations for evaluated general-purpose operating systems.
Framework focus does not mean that every product is certified, validated, authorized, or fully aligned to every listed framework. Confirm the exact baseline, version, cryptographic modules, evidence, and scope in the applicable product documentation and marketplace listing.
PRODUCTS
Foundation’s role is deliberately focused: deliver a hardened operating-system layer your team can test, approve, and build on.
Review marketplace optionsMISSION ENVIRONMENTS
Cloud infrastructure for agencies and programs operating under formal security controls and review.
Hardened operating-system starting points for defense-aligned systems and mission applications.
Repeatable baseline infrastructure for delivery teams supporting public-sector programs.
FIELD QUESTIONS
Every authorization context is different. These answers define where a hardened image helps and where customer responsibility continues.
Foundation Security provides hardened virtual machine infrastructure for government, defense, and federal-aligned cloud environments. The images create a more secure operating-system starting point for workloads deployed on supported cloud platforms.
No single virtual machine can make an entire system compliant or authorized. Foundation can help address operating-system configuration requirements, while your organization remains responsible for architecture, identity, networking, logging, application security, procedures, evidence, and authorization decisions.
Foundation focuses on DISA STIG, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 3, CMMC 2.0, FedRAMP Rev. 5, FIPS 140-3 readiness, FBI CJIS 6.1, CISA CPGs, NIST CSF 2.0, NIAP OSPP. This focus does not mean every image is certified, validated, or fully aligned to every framework. Confirm the product-specific baseline, version, evidence, and scope before deployment.
Foundation currently positions its virtual machines for AWS and Microsoft Azure environments. Product and operating-system availability can vary by marketplace, architecture, and region.
Yes. Secure defaults can restrict services, protocols, permissions, or authentication behavior an application expects. Test in a non-production environment and validate application requirements before promoting an image.
ESTABLISH THE BASELINE
Browse the Foundation catalog on AWS, open the Rocky Linux 9 product on Azure, or contact the team about platform and baseline requirements.