Security Compliance & Certifications for 22.04
Ubuntu goes through several rigorous security certifications and programs to meet common compliance requirements. All these security features are available with an Ubuntu Pro subscription.
FIPS 140-3
Federal Information Processing Standards Publications (FIPS) are issued by the National Institute of Standards and Technology (NIST). FIPS 140 specifies the security requirements for cryptographic modules. These requirements address the areas of secure design and implementation.
Ubuntu LTS releases have optional FIPS validated cryptographic packages, including the Linux kernel and OpenSSL, which are available with Ubuntu Pro. The full list of packages and certificates is available here.
Ubuntu 22.04 LTS is being certified against the new FIPS 140-3 standard. The cryptographic modules are reviewed by an independent testing lab before being officially certified by NIST. The list of modules in the testing phase is here, and the list of modules undergoing certification by NIST is here.
CIS
Ubuntu LTS releases have compliance benchmark documents developed by the Center for Internet Security (CIS). Ubuntu has developed the Ubuntu Security Guide to automate hardening Ubuntu LTS systems based off of the published CIS benchmarks. CIS benchmarks are available with the Ubuntu Security Guide for 22.04 LTS.
For more information see
- CIS Compliance with Ubuntu Security Guide for Ubuntu 20.04 and later
- CIS Compliance for Ubuntu 16.04 and 18.04.
DISA-STIG
Security Technical Implementation Guides (STIG) are developed by the Defense Information System Agency (DISA) for the U.S. Department of Defense (DoD). Ubuntu 22.04 has undergone evaluation by DISA; they have published the first version of the STIG, and we have incorporated it into the Ubuntu Security Guide.