Governance Domains
The three scored domains
Security, resilience and cost are scored and weighted. Delivery is collected but not scored, and is excluded from the published weights.
What is scored, and how much it counts
| Domain | Weight | The question it answers |
|---|---|---|
| Security | 0.5 | Are the controls that protect this environment passing? |
| Resilience | 0.3 | Does this environment survive failure, and can its data be recovered? |
| Cost | 0.2 | Is spend being consumed by resources that are demonstrably idle? |
The weights are published, printed in every board pack, and applied only when every offered domain was scored.
No silent renormalisation
If a domain could not be scored, the overall rating is withheld rather than recalculated across the remaining two.
Re-basing would mean the published weights no longer describe the calculation that was actually performed, and a reader recomputing from the methodology page would get a different answer from the one on the cover.
Delivery is not a fourth domain
Delivery governance evidence can be collected when a source repository is supplied. It is not scored, and it is excluded from the offered domains and from the published weights.
Assessing it properly requires read access to your source control, which the AWS-only authorization used by this engagement does not grant. Reporting it as an unassessed pillar would imply it was in scope. See Delivery, and why it is out of scope.
The floor on the overall band
The overall band can never be better than the security band. A green overall rating sitting above an amber security rating would be arithmetically defensible and governance nonsense.
