Skip to main content

DoD IL5

This page describes Department of Defense (DoD) Impact Level 5 (IL5) compliance controls in Databricks.

IL5 overview

DoD IL5 is a Department of Defense security categorization for cloud systems that process Controlled Unclassified Information (CUI) and certain types of National Security Systems (NSS) data. It builds on the FedRAMP High baseline with additional DoD-specific controls and restrictions.

What IL5 covers

  • Applies to DoD cloud systems handling CUI and NSS data.
  • Requires compliance with the FedRAMP High baseline plus DoD-specific controls defined in the DoD Cloud Computing Security Requirements Guide (SRG).
  • Available exclusively on Databricks for AWS GovCloud DoD, which is connected to the Non-classified Internet Protocol Router Network (NIPRNet).

Enable IL5 compliance controls

IL5 compliance controls are available on Databricks for AWS GovCloud DoD. The compliance security profile is enabled by default on all AWS GovCloud DoD workspaces, which adds monitoring agents, provides a hardened compute image, and enforces Nitro instance types for inter-node encryption. Automatic cluster update and enhanced security monitoring are also enabled.

AWS GovCloud DoD is a separate environment from other Databricks environments. To onboard to AWS GovCloud DoD, contact your Databricks account team. For setup requirements and configuration, see Databricks on AWS GovCloud.

You are solely responsible for verifying that sensitive information is never entered in customer-defined input fields, such as workspace names, compute resource names, tags, job names, job run names, network names, credential names, storage account names, and Git repository IDs or URLs. These fields might be stored, processed, or accessed outside the compliance boundary.

Regional support for features

This table shows feature availability for the selected compliance standard across all supported Databricks regions. Some features may be listed as available before they are actually released.

Feature

us-gov-west-1

AI Functions - Classification

AI Functions - Document Parsing

AI Functions - Information Extraction

Anomaly Detection

Classic Compute

Clean Rooms

Data Classification

Databricks Apps

Default Storage

Genie

Genie Agent Mode

Genie Code

Genie Code Agent Mode

Genie Code Dashboard Agent

Genie Spaces

Knowledge Assistant

Lakebase Autoscaling

Lakeflow Connect - Confluence

Lakeflow Connect - Dynamics 365

Lakeflow Connect - GA4

Lakeflow Connect - Google Ads

Lakeflow Connect - HubSpot

Lakeflow Connect - Meta Ads

Lakeflow Connect - MySQL

Lakeflow Connect - NetSuite

Lakeflow Connect - PostgreSQL

Lakeflow Connect - SFTP

Lakeflow Connect - Salesforce

Lakeflow Connect - ServiceNow

Lakeflow Connect - SharePoint

Lakeflow Connect - TikTok Ads

Lakeflow Connect - Workday HCM

Lakeflow Connect - Workday Reports (RaaS)

Lakeflow Connect - Zendesk Support

Lakeflow Connect - Zerobus Ingest

Lakeflow Jobs

Lakeflow Pipelines Editor

Lakehouse Monitoring

MLflow on Databricks

Managed MCP Servers

Model Serving - AI Gateway

Model Serving - AI Guardrail

Model Serving - AI Playground

Model Serving - Custom Models

Model Serving - External Models

Model Serving - Foundation Models AI Function (ai_query)

Model Serving - Foundation Models Pay-Per-Token

Predictive Optimization

Serverless Jobs/Workflows/Notebooks

Serverless Lakeflow Pipelines

Serverless SQL warehouses

Serverless Workspace

Supervisor Agent

Vector Search (Standard)

Vector Search (Storage Optimized)