Compliance profiles

When working with the Compliance Operator (CO), you can use the profiles provided by the Operator to meet industry standard benchmarks.

Note

The following tables reflect the latest available profiles in the Compliance Operator. The only supported versions of CIS and DISA STIG profiles will be the latest. Our recommendation to customers is to use ocp4-cis and ocp4-cis-node, ocp4-stig, and ocp4-stig-node, which always point to the latest version.

CIS compliance profiles
Table 24. Supported CIS compliance profiles
Profile Profile title Application Industry compliance benchmark Supported architectures Supported platforms

ocp4-cis [1]

CIS Red Hat Red Hat OpenShift Container Platform Benchmark v1.9.0

Platform

CIS Benchmarks ™ [4]

x86_64 ppc64le s390x aarch64

ocp4-cis-1-9[3]

CIS Red Hat Red Hat OpenShift Container Platform Benchmark v1.9.0

Platform

CIS Benchmarks ™ [4]

x86_64 ppc64le s390x aarch64

ocp4-cis-node [1]

CIS Red Hat Red Hat OpenShift Container Platform Benchmark v1.9.0

Node [2]

CIS Benchmarks ™ [4]

x86_64 ppc64le s390x aarch64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

ocp4-cis-node-1-9[3]

CIS Red Hat Red Hat OpenShift Container Platform Benchmark v1.9.0

Node [2]

CIS Benchmarks ™ [4]

x86_64 ppc64le s390x aarch64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

  1. The ocp4-cis and ocp4-cis-node profiles maintain the most up-to-date version of the CIS benchmark as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as CIS v1.9.0, use the ocp4-cis-1-9 and ocp4-cis-node-1-9 profiles.

  2. Node profiles must be used with the relevant Platform profile. For more information, see Compliance Operator profile types.

  3. All earlier CIS profiles are superceded by CIS v1.9.0. It is recommended to apply the latest profile to your environment.

  4. To locate the CIS Red Hat OpenShift Container Platform v4 Benchmark, go to CIS Benchmarks and click Download Latest CIS Benchmark, where you can then register to download the benchmark.

BSI Profile Support
Table 25. Supported BSI compliance profiles
Profile Profile title Application Industry compliance benchmark Supported architectures Supported platforms

ocp4-bsi [1]

BSI IT-Grundschutz (Basic Protection) Building Block SYS.1.6 and APP.4.4

Platform

BSI Basic Protection Compendium

x86_64

ocp4-bsi-node [1]

BSI IT-Grundschutz (Basic Protection) Building Block SYS.1.6 and APP.4.4

Node [2]

BSI Basic Protection Compendium

x86_64

rhcos4-bsi [1]

BSI IT-Grundschutz (Basic Protection) Building Block SYS.1.6 and APP.4.4

Node [2]

BSI Basic Protection Compendium

x86_64

ocp4-bsi-2022 [3]

BSI IT-Grundschutz (Basic Protection) Building Block SYS.1.6 and APP.4.4

Platform

BSI Basic Protection Compendium

x86_64

ocp4-bsi-node-2022 [3]

BSI IT-Grundschutz (Basic Protection) Building Block SYS.1.6 and APP.4.4

Node [2]

BSI Basic Protection Compendium

x86_64

rhcos4-bsi-2022 [3]

BSI IT-Grundschutz (Basic Protection) Building Block SYS.1.6 and APP.4.4

Node [2]

BSI Basic Protection Compendium

x86_64

  1. The ocp4-bsi, ocp4-bsi-node, and rhcos4-bsi profiles maintain the most up-to-date version of the BSI Basic Protection Profile as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as BSI 2022, use the ocp4-bsi-2022, ocp4-bsi-node-2022 or rhcos4-bsi-2022 profiles.

  2. Node profiles must be used with the relevant Platform profile. For more information, see Compliance Operator profile types.

  3. Edition 2022 is the latest available English edition of the BSI IT-Grundschutz (Basic Protection) compendium. There were no changes for Building Blocks SYS.1.6 and APP.4.4, SYS.1.1, and SYS.1.3 in the latest published German compendium (edition 2023).

For more information, see BSI Quick Check.

Essential Eight compliance profiles
Table 26. Supported Essential Eight compliance profiles
Profile Profile title Application Industry compliance benchmark Supported architectures Supported platforms

ocp4-e8

Australian Cyber Security Centre (ACSC) Essential Eight

Platform

ACSC Hardening Linux Workstations and Servers

x86_64

rhcos4-e8

Australian Cyber Security Centre (ACSC) Essential Eight

Node

ACSC Hardening Linux Workstations and Servers

x86_64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

FedRAMP High compliance profiles
Important

Applying automatic remediations to any profile, such as rhcos4-stig, that uses the service-sshd-disabled rule, automatically disables the sshd service. This situation blocks SSH access to control plane nodes and compute nodes. To keep the SSH access enabled, create a TailoredProfile object and set the rhcos4-service-sshd-disabled rule value for the disableRules parameter.

Table 27. Supported FedRAMP High compliance profiles
Profile Profile title Application Industry compliance benchmark Supported architectures Supported platforms

ocp4-high [1]

NIST 800-53 High-Impact Baseline for Red Hat OpenShift - Platform level

Platform

NIST SP-800-53 Release Search

x86_64

ocp4-high-node [1]

NIST 800-53 High-Impact Baseline for Red Hat OpenShift - Node level

Node [2]

NIST SP-800-53 Release Search

x86_64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

ocp4-high-node-rev-4

NIST 800-53 High-Impact Baseline for Red Hat OpenShift - Node level

Node [2]

NIST SP-800-53 Release Search

x86_64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

ocp4-high-rev-4

NIST 800-53 High-Impact Baseline for Red Hat OpenShift - Platform level

Platform

NIST SP-800-53 Release Search

x86_64

rhcos4-high [1]

NIST 800-53 High-Impact Baseline for Red Hat Enterprise Linux CoreOS

Node

NIST SP-800-53 Release Search

x86_64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

rhcos4-high-rev-4

NIST 800-53 High-Impact Baseline for Red Hat Enterprise Linux CoreOS

Node

NIST SP-800-53 Release Search

x86_64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

  1. The ocp4-high, ocp4-high-node and rhcos4-high profiles maintain the most up-to-date version of the FedRAMP High standard as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as FedRAMP high R4, use the ocp4-high-rev-4 and ocp4-high-node-rev-4 profiles.

  2. Node profiles must be used with the relevant Platform profile. For more information, see Compliance Operator profile types.

FedRAMP Moderate compliance profiles
Table 28. Supported FedRAMP Moderate compliance profiles
Profile Profile title Application Industry compliance benchmark Supported architectures Supported platforms

ocp4-moderate [1]

NIST 800-53 Moderate-Impact Baseline for Red Hat OpenShift - Platform level

Platform

NIST SP-800-53 Release Search

x86_64 ppc64le s390x aarch64

ocp4-moderate-node [1]

NIST 800-53 Moderate-Impact Baseline for Red Hat OpenShift - Node level

Node [2]

NIST SP-800-53 Release Search

x86_64 ppc64le s390x aarch64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

ocp4-moderate-node-rev-4

NIST 800-53 Moderate-Impact Baseline for Red Hat OpenShift - Node level

Node [2]

NIST SP-800-53 Release Search

x86_64 ppc64le s390x aarch64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

ocp4-moderate-rev-4

NIST 800-53 Moderate-Impact Baseline for Red Hat OpenShift - Platform level

Platform

NIST SP-800-53 Release Search

x86_64 ppc64le s390x aarch64

rhcos4-moderate [1]

NIST 800-53 Moderate-Impact Baseline for Red Hat Enterprise Linux CoreOS

Node

NIST SP-800-53 Release Search

x86_64 aarch64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

rhcos4-moderate-rev-4

NIST 800-53 Moderate-Impact Baseline for Red Hat Enterprise Linux CoreOS

Node

NIST SP-800-53 Release Search

x86_64 aarch64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

  1. The ocp4-moderate, ocp4-moderate-node and rhcos4-moderate profiles maintain the most up-to-date version of the FedRAMP Moderate standard as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as FedRAMP Moderate R4, use the ocp4-moderate-rev-4 and ocp4-moderate-node-rev-4 profiles.

  2. Node profiles must be used with the relevant Platform profile. For more information, see Compliance Operator profile types.

NERC-CIP compliance profiles
Table 29. Supported NERC-CIP compliance profiles
Profile Profile title Application Industry compliance benchmark Supported architectures Supported platforms

ocp4-nerc-cip

North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) cybersecurity standards profile for the Red Hat OpenShift Container Platform - Platform level

Platform

NERC CIP Standards

x86_64

ocp4-nerc-cip-node

North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) cybersecurity standards profile for the Red Hat OpenShift Container Platform - Node level

Node [1]

NERC CIP Standards

x86_64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

rhcos4-nerc-cip

North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) cybersecurity standards profile for Red Hat Enterprise Linux CoreOS

Node

NERC CIP Standards

x86_64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

  1. Node profiles must be used with the relevant Platform profile. For more information, see Compliance Operator profile types.

PCI-DSS compliance profiles
Table 30. Supported PCI-DSS compliance profiles
Profile Profile title Application Industry compliance benchmark Supported architectures Supported platforms

ocp4-pci-dss [1]

PCI-DSS v4 Control Baseline for Red Hat OpenShift Container Platform 4

Platform

PCI Security Standards ® Council Document Library

x86_64 ppc64le aarch64

ocp4-pci-dss-3-2 [3]

PCI-DSS v3.2.1 Control Baseline for Red Hat OpenShift Container Platform 4

Platform

PCI Security Standards ® Council Document Library

x86_64 ppc64le s390x aarch64

ocp4-pci-dss-4-0

PCI-DSS v4 Control Baseline for Red Hat OpenShift Container Platform 4

Platform

PCI Security Standards ® Council Document Library

x86_64 ppc64le aarch64

ocp4-pci-dss-node [1]

PCI-DSS v4 Control Baseline for Red Hat OpenShift Container Platform 4

Node [2]

PCI Security Standards ® Council Document Library

x86_64 ppc64le aarch64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

ocp4-pci-dss-node-3-2 [3]

PCI-DSS v3.2.1 Control Baseline for Red Hat OpenShift Container Platform 4

Node [2]

PCI Security Standards ® Council Document Library

x86_64 ppc64le s390x aarch64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

ocp4-pci-dss-node-4-0

PCI-DSS v4 Control Baseline for Red Hat OpenShift Container Platform 4

Node [2]

PCI Security Standards ® Council Document Library

x86_64 ppc64le aarch64

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

  1. The ocp4-pci-dss and ocp4-pci-dss-node profiles maintain the most up-to-date version of the PCI-DSS standard as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as PCI-DSS v3.2.1, use the ocp4-pci-dss-3-2 and ocp4-pci-dss-node-3-2 profiles.

  2. Node profiles must be used with the relevant Platform profile. For more information, see Compliance Operator profile types.

  3. PCI-DSS v3.2.1 is superceded by PCI-DSS v4. It is recommended to apply the latest profile to your environment.

STIG compliance profiles
Important

Applying automatic remediations to any profile, such as rhcos4-stig, that uses the service-sshd-disabled rule, automatically disables the sshd service. This situation blocks SSH access to control plane nodes and compute nodes. To keep the SSH access enabled, create a TailoredProfile object and set the rhcos4-service-sshd-disabled rule value for the disableRules parameter.

Table 31. Supported STIG compliance profiles
Profile Profile title Application Industry compliance benchmark Supported architectures Supported platforms

ocp4-stig [1]

Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat OpenShift[3]

Platform

DISA-STIG

x86_64 ppc64le

ocp4-stig-node [1]

Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat OpenShift[3]

Node [2]

DISA-STIG

x86_64 ppc64le

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

ocp4-stig-v2r3

Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat OpenShift V2R3

Platform

DISA-STIG

x86_64 ppc64le

ocp4-stig-node-v2r3 [1]

Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat OpenShift V2R3

Node

DISA-STIG

x86_64 ppc64le

rhcos4-stig[1]

Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat OpenShift[3]

Node

DISA-STIG

x86_64 ppc64le

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

rhcos4-stig-v2r3

Defense Information Systems Agency Security Technical Implementation Guide (DISA STIG) for Red Hat OpenShift V2R3

Node

DISA-STIG

x86_64 ppc64le

Red Hat OpenShift Service on AWS with hosted control planes (ROSA HCP)

  1. The ocp4-stig, ocp4-stig-node and rhcos4-stig profiles maintain the most up-to-date version of the DISA-STIG benchmark as it becomes available in the Compliance Operator. If you want to adhere to a specific version, such as DISA-STIG V2R3, use the ocp4-stig-v2r3 and ocp4-stig-node-v2r3 profiles.

  2. Node profiles must be used with the relevant Platform profile. For more information, see Compliance Operator profile types.

  3. DISA-STIG V1R2 is superceded by DISA-STIG V2R3. It is recommended to apply the latest profile to your environment.

About extended compliance profiles

Some compliance profiles have controls that require following industry best practices, resulting in some profiles extending others. Combining the Center for Internet Security (CIS) best practices with National Institute of Standards and Technology (NIST) security frameworks establishes a path to a secure and compliant environment.

For example, the NIST High-Impact and Moderate-Impact profiles extend the CIS profile to achieve compliance. As a result, extended compliance profiles eliminate the need to run both profiles in a single cluster.

Table 32. Profile extensions
Profile Extends

ocp4-pci-dss

ocp4-cis

ocp4-pci-dss-node

ocp4-cis-node

ocp4-high

ocp4-cis

ocp4-high-node

ocp4-cis-node

ocp4-moderate

ocp4-cis

ocp4-moderate-node

ocp4-cis-node

ocp4-nerc-cip

ocp4-moderate

ocp4-nerc-cip-node

ocp4-moderate-node