Assessment Methodology
What is excluded, and why
Records that cannot be classified are excluded from both sides of the pass rate, and the excluded count is reported rather than hidden.
Records that cannot be classified
A control record whose compliance status is unavailable, or which carries no classifiable status, is excluded from both the numerator and the denominator of the pass rate.
Counting it as a pass would flatter the score. Counting it as a failure would misstate it. Excluding it is the only honest option, and the count of exclusions is reported in the pack.
Files that are not control evidence
Only files recognised as control evidence are scored. Any other file present in the evidence directory is listed in the assessment note and ignored, rather than parsed hopefully and misread.
Severities never collected
Low and informational controls are never collected. The scan is invoked at critical, high and medium only.
That is a scoping decision, and it changes the denominator of the security pass rate. Widening it would change every score at once, which is why it is recorded as part of the methodology rather than left as a command-line detail. See The control contract.
Checks the access boundary prevents
Three families of check cannot run because the actions they need are denied outright. They are absent, not passing. See What the boundary costs in coverage.
Signals with no resources
A resilience signal with no in-scope resources is recorded and excluded from scoring. An account with no databases is not penalised for having no database backups.
