Governance Domains
Security
Scored as a weighted control pass rate over distinct controls, adjusted for posture, with a ceiling that no critical failure can pass.
Weight: 0.5, the largest of the three.
What is measured
A weighted control pass rate over distinct controls. Each control counts once, whatever the number of resources it was evaluated against, and is weighted by its severity.
| Severity | Weight |
|---|---|
| Critical | 10 |
| High | 6 |
| Medium | 3 |
| Low | 1 |
The low weight is retained so the table is complete. Low controls are never collected, so it is never applied.
Both halves are required
Passing and failing results are both needed. Without a denominator there is no rate, and the domain is reported as not assessed rather than scored from failures alone.
Posture penalties
Security Hub posture is read as context and applied as a penalty to the domain score:
| Observation | Penalty |
|---|---|
| Security Hub disabled | 12 |
| Finding aggregation disabled | 6 |
| No delegated administrator | 4 |
The critical ceiling
A weighted pass rate can absorb a handful of critical failures behind a large number of passing controls. The band is therefore capped: green requires zero failing critical controls, and five or more force red.
The ceiling is applied to the band, never to the score, so the arithmetic stays inspectable. See The critical ceiling.
Minimum population
Below 25 evaluated controls the domain is not rated. A single passing control is not evidence of security governance, and the observations are still reported.
Not assessed when
Control checks did not run, only one side of the result set was returned, or the population was below the minimum.
