Evidence & Findings
Materiality, not severity
Why the reach of a control failure in your own account is a different measure from the severity a scanner assigns it in the abstract.
Severity is not materiality
Severity is the scanner's judgement of a control in the abstract. It is identical for every customer in the world, and it cannot distinguish a medium control failing on forty resources across five regions from a critical failing on one.
Materiality is how far that failure reaches in this account.
The bands
| Band | Condition |
|---|---|
| Estate-wide | Governs the account as a whole, or failed on 10 or more distinct resources, or failed in every region it was evaluated in |
| Broad | Failed on 2 or more distinct resources, or failures span more than one region |
| Contained | Exactly one distinct resource failed |
| Not determinable | The evidence carried no resource identifier. Reach is not guessed at |
The two adjustments
A critical control whose concern is externally reachable and whose class is preventive is escalated one band, capped at estate-wide. An open door anyone can reach carries further than its resource count suggests.
A detective control is never escalated by severity. A missing alarm is a visibility gap, not an open door, and inflating it would make the band meaningless where it matters.
Every band shows its working
Each band carries the identifiers of the rules that produced it, and the pack prints them. A band a reader cannot check is an opinion.
What it does not model
Nothing about your business. Not revenue, not data value, not workload criticality, not customer impact, not regulatory position, and not the probability of compromise. The assessment observes none of those and must not imply them.
Related
- Materiality - the canonical definition
- Materiality rules M0 to M6
- Severity vs materiality
