Structured Hardening Project

About SHP

The purpose, boundaries, and institutional role of the Structured Hardening Project.

About the Structured Hardening Project

The Structured Hardening Project develops and maintains a technical standard for bounded, verifiable system hardening.

SHP exists to make security posture more explicit.

Instead of treating hardening as a collection of recommended settings, SHP connects defined threat models, controls, evidence, deterministic verification, and governed certification.

What SHP is

SHP is a structured hardening standard.

Its purpose is to define:

  • what a certification target is intended to protect against
  • which controls apply
  • how those controls are implemented
  • how their resulting state is verified
  • how certification decisions are made
  • how certification authenticity is established
  • how expiry, revocation, and drift affect certification status

The applicable specifications provide the technical authority for those rules.

What SHP is not

SHP is not a claim that systems can be made universally secure.

It is not:

  • a guarantee against compromise
  • a generic security checklist
  • a vulnerability scanner
  • a security score
  • general IT support
  • a managed security service
  • continuous monitoring
  • incident response

Certification is deliberately bounded by platform, threat model, controls, evaluated state, specification versions, and time.

Why structured hardening

Security configuration is easy to describe informally and difficult to prove consistently.

A statement such as “this machine has been hardened” says very little unless the underlying questions can also be answered:

What threat model was used?

Which controls were required?

Which controls were actually applicable?

What evidence shows that they are present?

What happens when a mandatory control fails?

What exactly was certified?

When does that certification stop representing the current state?

SHP is designed to make those questions explicit.

Verification before assertion

SHP treats verification as part of the hardening model rather than as an optional final inspection.

Controls must define verifiable outcomes.

Verification must produce structured results under versioned rules.

Certification decisions must map to those results.

Where the required state cannot be established, uncertainty must not be silently converted into success.

Bounded claims

SHP deliberately avoids universal security claims.

A valid certification means what its applicable specifications, scope, verification evidence, certification class or tier, and validity period say it means.

Nothing more should be inferred.

This is why bounded certification, exclusions, residual risk, expiry, revocation, and drift are explicit parts of the model.

Open verification and controlled certification

Verification and certification have different trust boundaries.

Verification tooling is intended to be open, deterministic, versioned, reproducible, and machine-readable.

Certification authority remains controlled under the SHP trust architecture.

Independent execution of SHP verification tooling does not grant certification authority.

Platform discipline

SHP does not assume that security controls can be transferred safely between platforms.

Platform support requires formal definition.

A new operating system, device class, network platform, or other certification domain must not become “supported” merely because similar controls exist elsewhere.

Its scope and threat model must be defined before certification controls can be established.

Governance

SHP specifications are versioned and governed.

Changes must preserve historical meaning.

Certification must not silently change meaning because a later specification was published.

Where requirements change, the applicable version and amendment history provide the context necessary to interpret both current and historical certification.

Services under the standard

Certification services may be provided under SHP.

Those services apply the standard; they do not redefine it.

The distinction matters:

The standard defines the requirements.

Verification evaluates the observed state.

Certification records a governed result.

Services provide a way to perform that work.

The SHP Standard · Specifications · Services