Governance Domains

Security

Scored as a weighted control pass rate over distinct controls, adjusted for posture, with a ceiling that no critical failure can pass.

Currentengine 9.0.0Verified 2026-08-30

Weight: 0.5, the largest of the three.

What is measured

A weighted control pass rate over distinct controls. Each control counts once, whatever the number of resources it was evaluated against, and is weighted by its severity.

SeverityWeight
Critical10
High6
Medium3
Low1

The low weight is retained so the table is complete. Low controls are never collected, so it is never applied.

Both halves are required

Passing and failing results are both needed. Without a denominator there is no rate, and the domain is reported as not assessed rather than scored from failures alone.

Posture penalties

Security Hub posture is read as context and applied as a penalty to the domain score:

ObservationPenalty
Security Hub disabled12
Finding aggregation disabled6
No delegated administrator4

The critical ceiling

A weighted pass rate can absorb a handful of critical failures behind a large number of passing controls. The band is therefore capped: green requires zero failing critical controls, and five or more force red.

The ceiling is applied to the band, never to the score, so the arithmetic stays inspectable. See The critical ceiling.

Minimum population

Below 25 evaluated controls the domain is not rated. A single passing control is not evidence of security governance, and the observations are still reported.

Not assessed when

Control checks did not run, only one side of the result set was returned, or the population was below the minimum.