Limitations
What the numbers do not mean
Each figure in the pack paired with the interpretation it does not support, so nothing is read as a claim the assessment cannot make.
| The number | Does not mean |
|---|---|
| Overall score | A certification, an audit opinion, or a comparison against anyone else |
| Domain score | That the domain is fully covered. It is covered to the extent published |
| RAG band | A risk appetite judgement. It is a threshold, applied uniformly |
| Controls failed | A count of problems. It is a count of distinct controls, which is not the same |
| Controls evaluated | Everything that could be checked. It is what this scanner checks at these severities |
| Materiality band | Business consequence. It is reach within the account, and nothing else |
| Exposure range | A loss estimate, an actuarial figure, a likelihood, or a prediction |
| Evidenced waste | Total possible savings. It is three classes of demonstrably idle resource |
| Evidence confidence | Confidence that the findings are correct. It is a measure of how many domains were scored |
| Closed findings | That the environment improved, unless the not-re-assessed count is also read |
The two most easily misread
Exposure. It is an indicative magnitude from the count and severity of failed controls. It contains no likelihood term, uses no external loss data, is not actuarial, and excludes cloud cost recovery. The exact sum is never printed precisely because seven significant figures would invite it to be read as a measurement.
Evidence confidence. High confidence means three governance domains were scored. It does not mean the individual control results have been verified against your account. Nobody has done that. See What GovIntel validates about itself.
What the numbers do mean
That a defined set of controls, over a stated scope, at a stated time, produced a stated result under a published methodology you can recompute from the pack itself.
