| CPC G06F 21/577 (2013.01) [G06F 21/6218 (2013.01)] | 15 Claims |

|
1. A method comprising:
scanning, by a first computer system, a cluster including a plurality of virtual machines;
detecting, based on the scanning the cluster of virtual machines, a first content change of the cluster that includes at least one of:
an update to data of at least one file on at least a first one of the virtual machines,
adding or removing at least one file from the first one of the virtual machines, and
an addition of at least one virtual machine to the cluster or a removal of at least one virtual machine from the cluster;
determining, in response to the detecting of the first content change, a content-based security level of the cluster;
comparing the determined content-based security level of the cluster to a security level standard of the cluster;
determining a difference between the determined content-based security level and the security level standard; and
performing, in response to determining the difference, an update to a security setting of the cluster.
|