Prioritize the workload
Start with the service consequence and threat exposure so the team knows why this particular baseline matters.
FRAMEWORKS / CISA CPGS
Use supported operating-system images as a concrete infrastructure action within a broader set of prioritized cybersecurity outcomes for critical infrastructure.
PROGRAM CONTEXT
CISA's Cross-Sector Cybersecurity Performance Goals are voluntary, prioritized practices for IT and OT owners. A hardened image can support selected infrastructure outcomes, while identity, network design, monitoring, recovery, and operational practice remain separate responsibilities.
Start with the service consequence and threat exposure so the team knows why this particular baseline matters.
Select an OS, release, architecture, and product profile that can be maintained within the team's actual operating model.
Test the deployed system and preserve evidence that connects the image baseline to the wider security action.
IMAGE SELECTION
Use the prioritized outcome to frame the decision, then select and validate the exact image that fits the workload and operating team.
Use the named profile and product scope—not the page headline—as the description of image-level hardening.
Confirm application support, release lifecycle, package behavior, and the team's ability to maintain the platform.
Choose x86_64 or arm64 against workload compatibility, tooling, performance, and support requirements.
Test identity, networking, applications, monitoring, recovery, exceptions, and operating procedures before production use.
SECTOR ROUTES
The same program can lead to different infrastructure decisions when uptime, access, ownership, and service consequences change.
NEXT STEP