01 · THE STANDARD
Five artifacts, each answering a different audit question.
Maps image-level safeguards to the PCI DSS requirement areas they can help address, with scope and limitations stated.
Records the security configuration standard applied to the operating system, including material exceptions and cloud-specific adaptations.
Identifies the assessment tool, baseline, release, date, and known exceptions. A scan result is evidence about that image—not a statement about the buyer’s workload.
Lists operating-system packages present in the published release so teams can evaluate dependencies and vulnerability findings.
Connects each published image version to its release date, base operating system, and patch cycle.
02 · PUBLICATION STATUS
Planned does not mean published.
Until an artifact is linked from this site or the corresponding Marketplace record, buyers should treat it as unavailable.
| Artifact | Public status | Current source |
|---|---|---|
| Architecture and purchase record | Published | RHEL 9 product record |
| Control mapping | Standardizing | This page defines the publication standard |
| Hardening manifest | Standardizing | Per-image publication pending |
| Scan context | Standardizing | Per-image publication pending |
| SBOM | Standardizing | Per-image publication pending |
| Patch history | Partial | Public changelog methodology |
03 · HOW TO USE IT
Give the pack to engineering and the assessor early.
- 01Confirm the exact release and architecture.
Evidence must match the image version being evaluated.
- 02Review exceptions before deploying.
Hardening can affect services, authentication, logging, cryptography, and application assumptions.
- 03Map the image into the responsibility matrix.
Use image evidence for the OS layer and retain separate evidence for the surrounding AWS environment.
04 · EVIDENCE BOUNDARY
An evidence pack narrows review. It does not complete it.
Application security, PCI scope, AWS architecture, IAM, networking, data flows, logging operations, incident response, evidence retention, and assessor validation remain customer responsibilities.
Customers and assessors should validate Citadel images using tools and procedures appropriate to their environment and assessment scope.