SovereignCloudStack / SovereignCloudStack/standards
Define a Standard for the security of the Hardware Layer
@depressiveRobot is already working on this.
Since Feb 19, 2026.
- Dominant language
- Python
- Stars
- 47
- Forks
- 38
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 8
Description
In https://github.com/SovereignCloudStack/standards/issues/749 we are standardizing the security of the software of the IaaS Layer.
But integrating security patches and updates are not solely done on one layer, but need to be accomplished by CSPs on all Layers.
This issue should investigate which measures should be done on the HARDWARE layer to prevent and deal with security issues.
It should be included, how CSPs could get information about potential security issues.
How fast they should respond according to the severity? (see C5 criteria catalog with timeframes for responses on page 75. )
Definition of Done:
Please refer to scs-0001-v1 for details.
- Proposal has been written with name of the form
scs-xxxx-v1-slug.md(only substituteslug) - Proposal has the fields
status,type,trackset - Proposal has been voted upon in the corresponding team
- Status has been changed into
Draft, file renamed:xxxxreplaced by document number - If applicable: test script has been written (this item may be moved into a separate issue so long as the state is
Draft)
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.