Assessment Methodology
Methodology principles
Four commitments the scoring keeps: deterministic, fully disclosed, silent about what it cannot evidence, and never scoring absence as zero.
Deterministic
The same evidence produces the same score. Nothing in the scoring samples, estimates, weights by judgement at run time, or varies between runs.
Disclosed in full
Every threshold, weight, ceiling and rule the engine applies is defined in a configuration file, and reproduced on the methodology page of the board pack. A reader can recompute the result from what the pack prints.
Silent about what it cannot evidence
A domain the evidence cannot support is reported as not assessed, with the population stated. It is never scored as zero and never quietly omitted, because those two mislead in opposite directions and both cost trust.
Absence is not a failure
An account that runs no databases is not penalised for having no database backups. A signal with no in-scope resources is recorded and excluded from scoring rather than counted against you.
The rules these produce
| Rule | Effect |
|---|---|
| Control deduplication | Records are collapsed to distinct controls before scoring |
| Indeterminate exclusion | A record that cannot be classified is excluded from both numerator and denominator, and the excluded count is reported |
| Evidence admission | Only files recognised as control evidence are scored. Anything else is listed and ignored |
| Overall RAG floor | The overall band can never be better than the security band |
| No silent renormalisation | The overall score is calculated only when every offered domain was scored. A missing domain withholds the rating rather than re-basing across the rest |
| Confidence gate | The overall rating is withheld entirely when confidence is below High |
What none of it does
No part of the scoring models revenue, data value, workload criticality, regulatory position, or the probability of compromise. The assessment observes none of those. See What the scores do not mean.
