FOUNDATION SECURITY

FEDERAL · DEFENSE · GOVERNMENT

A secure foundation for systems that serve.

DISA STIG and NIST-aligned infrastructure for government teams that need a hardened operating-system baseline before the mission begins.

17 notable organizations10 framework focus areasAWS and AzureFederal and defense focus

NOTABLE ORGANIZATIONS

A footprint weighted toward public service and national security.

Foundation supports security-conscious teams across government, defense, and the enterprise partners that serve them.

Organization names and marks identify notable Foundation users. They do not imply endorsement, sponsorship, partnership, or government approval of Foundation Security.

THE FOUNDATION PRINCIPLE

Infrastructure security should begin before an application is installed.

Foundation gives public-sector teams a maintained starting point for the operating-system layer, reducing repetitive baseline work while leaving system ownership and authorization decisions where they belong.

CAPABILITIES

Controls become useful when they become deployable.

Foundation translates security guidance into cloud infrastructure that can be evaluated, tested, and launched through established workflows.

Hardened baselines

Operating-system configurations aligned to recognized security guidance before a workload reaches production.

Framework alignment

A defined starting point for teams working across DISA STIG, NIST, CMMC, FedRAMP, CJIS, and related requirements.

Cloud delivery

Virtual machine products distributed through current AWS and Azure Marketplace destinations.

Technical support

Human assistance for product launch, marketplace access, and configuration behavior.

Explore all capabilities

SECURITY + COMPLIANCE FOCUS

Ten frameworks. One operating-system foundation.

Foundation focuses on infrastructure that can support federal, defense, public-safety, and regulated-system requirements. Alignment depends on the specific product and system boundary.

DISA STIG

Secure configuration baselines for Department of Defense information systems.

NIST SP 800-53 Rev. 5

Federal security and privacy control families for information systems and organizations.

NIST SP 800-171 Rev. 3

Requirements for protecting controlled unclassified information in nonfederal systems.

CMMC 2.0

Defense industrial base assessment expectations for safeguarding federal contract information and CUI.

FedRAMP Rev. 5

Cloud authorization control baselines derived from NIST SP 800-53 Revision 5.

FIPS 140-3 readiness

Readiness considerations for cryptographic-module requirements within the broader system boundary.

FBI CJIS 6.1

Security policy considerations for systems that process criminal justice information.

CISA CPGs

Cross-sector cybersecurity performance goals for reducing common and consequential risks.

NIST CSF 2.0

Governance and risk-management outcomes across identify, protect, detect, respond, and recover functions.

NIAP OSPP

Operating System Protection Profile considerations for evaluated general-purpose operating systems.

Framework focus does not mean that every product is certified, validated, authorized, or fully aligned to every listed framework. Confirm the exact baseline, version, cryptographic modules, evidence, and scope in the applicable product documentation and marketplace listing.

PRODUCTS

A stronger state at first boot.

Foundation’s role is deliberately focused: deliver a hardened operating-system layer your team can test, approve, and build on.

Review marketplace options
Platforms
AWS and Microsoft Azure
Operating systems
Linux and Windows product families where listed
Primary buyers
Federal, defense, and government delivery teams
Scope
Operating-system baseline and product-specific support

MISSION ENVIRONMENTS

Built for teams accountable to more than uptime.

Federal civilian

Cloud infrastructure for agencies and programs operating under formal security controls and review.

Defense workloads

Hardened operating-system starting points for defense-aligned systems and mission applications.

Government integrators

Repeatable baseline infrastructure for delivery teams supporting public-sector programs.

Review mission environments

FIELD QUESTIONS

Clear boundaries. Stronger decisions.

Every authorization context is different. These answers define where a hardened image helps and where customer responsibility continues.

What does Foundation Security provide?

Foundation Security provides hardened virtual machine infrastructure for government, defense, and federal-aligned cloud environments. The images create a more secure operating-system starting point for workloads deployed on supported cloud platforms.

Do Foundation images make a system compliant?

No single virtual machine can make an entire system compliant or authorized. Foundation can help address operating-system configuration requirements, while your organization remains responsible for architecture, identity, networking, logging, application security, procedures, evidence, and authorization decisions.

Which frameworks are in focus for Foundation?

Foundation focuses on DISA STIG, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 3, CMMC 2.0, FedRAMP Rev. 5, FIPS 140-3 readiness, FBI CJIS 6.1, CISA CPGs, NIST CSF 2.0, NIAP OSPP. This focus does not mean every image is certified, validated, or fully aligned to every framework. Confirm the product-specific baseline, version, evidence, and scope before deployment.

Where can Foundation images run?

Foundation currently positions its virtual machines for AWS and Microsoft Azure environments. Product and operating-system availability can vary by marketplace, architecture, and region.

Can hardening affect an application?

Yes. Secure defaults can restrict services, protocols, permissions, or authentication behavior an application expects. Test in a non-production environment and validate application requirements before promoting an image.

ESTABLISH THE BASELINE

Build the mission on a hardened foundation.

Browse the Foundation catalog on AWS, open the Rocky Linux 9 product on Azure, or contact the team about platform and baseline requirements.