One of the most important measures is never to operate the hypervisor directly on the Internet. This reduces the greatest risk.
Otherwise, what you want depends largely on your requirements. Frameworks such as ISO 27001 or PCI-DSS can provide you with possible measures that make sense.