The Pod Security Standards, which replaced PodSecurityPolicy (removed in 1.25), are three cumulative levels:
Privileged allows everything, for trusted system add-ons such as CNI, CSI and log agents.
Baseline blocks the known ways out of a container onto the node: privileged mode, host namespaces, hostPath volumes, host ports and added capabilities. Most images pass it unchanged.
Restricted also demands proof of harmlessness on every container: runAsNonRoot: true, allowPrivilegeEscalation: false, capabilities: { drop: [ALL] } and seccompProfile: { type: RuntimeDefault }.