Security Certifications
Our security certifications validate the highest standards of security, compliance and trust, ensuring mission-critical workloads and operations is always protected.
CIS Benchmarks
The Center for Internet Security (CIS – https://www.cisecurity.org/benchmark/kubernetes/) is an accepted third-party and nonprofit organization whose mission is to “identify, develop, validate, promote, and sustain best practice solutions for cyber defense and build and lead communities to enable an environment of trust in cyberspace” (https://www.cisecurity.org/about-us/).
RGS takes these benchmarks and either builds the controls directly into RKE2 or allows for the configuration to be applied extremely easily via automated scripts and input parameters. In addition to applying the benchmarks, we also build tools that can periodically scan security configurations to enforce this compliance.
Enumerating the controls contained in these documents can also provide a large body of evidence needed for security approvals.
Consult the following resources for information about hardening your cluster according to the CIS benchmarks:
- RKE2 CIS Hardening Guide - https://docs.rke2.io/security/hardening_guide/
- RKE2 CIS Self-Assessment Guide - https://docs.rke2.io/security/cis_self_assessment19
- CIS Automated Scanning - https://rancher.com/docs/rancher/v2.x/en/cis-scans/v2.5/
- Rancher CIS Hardening Guide - https://rancher.com/docs/rancher/v2.x/en/security/rancher-2.5/1.6-hardening-2.5/
- Rancher CIS Self-Assessment Guide - https://rancher.com/docs/rancher/v2.x/en/security/rancher-2.5/1.6-benchmark-2.
CMMC Level 2 Certified
Rancher Government Solutions (RGS) is among the estimated first 1% of U.S. government contractors to earn Cybersecurity Maturity Model Certification (CMMC) Level 2 through a certified third-party assessment. This certification confirms that RGS meets the Department of Defense’s security standards for protecting Controlled Unclassified Information (CUI) within contractor systems.Achieving this certification took more than 150 documented policies, procedures, and controls, all developed and implemented by a small internal team. RGS completed the process with no open action items (POA&Ms), a result few organizations achieve. This places us in a select group of early certified contractors and positions us to assist federal partners seeking their own CMMC assessments.
- More information: CMMC Accreditation Body
- RGS CMMC SPRS: L200000463
DISA STIG Guides
Rancher Government Solutions is currently in the process of developing and maintaining Rancher and RKE2 STIGs with DISA. We allow our customers to access these in-flight for further reference and encourage any feedback you may have.
Rancher STIG
- More information: https://public.cyber.mil/?s=rancher+stig
- Download Zip File: https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RGS_MCM_V2R1_STIG.zip
RKE2 STIG
- More information: https://public.cyber.mil/?s=rancher+stig
- Download Zip File: https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RGS_RKE2_V2R3_STIG.zip
NIST - FIPS 140-2 Certified
The Federal Information Processing Standard, FIPS, is a U.S. Government security standard used to approve cryptographic modules. Rancher Government Solutions delivers secure Kubernetes to federal programs with certified FIPS-140-2 cryptographic libraries for RKE2.
- Cryptographic Module Validation Program (CMVP)
- Certificate #4691
- More Information: https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4691
