Risk & Scoring
How Resilience is scored
The mean coverage ratio across signals that have in-scope resources, issued only when both availability and recoverability were observable.
The calculation
- Collect five configuration signals, each a coverage ratio over real resources.
- Discard signals with no in-scope resources. An account with no databases is not penalised for having no database backups.
- Check the gate: both governance concerns must be evidenced, across at least the minimum number of distinct applicable resources.
- If the gate passes, the score is the mean coverage across the surviving signals.
The gate
| Concern | Signals |
|---|---|
| Availability | Database multi-zone, auto scaling multi-zone, load balancer multi-zone |
| Recoverability | Database automated backups, object storage versioning |
Both concerns must be evidenced. Where only one is observable the domain is reported as not assessed, and every observed signal is still printed with its denominator.
Counted per family, not per signal
Resources are counted once per resource family. A service exposing two signals from a single population does not count twice.
Without that, a database-only estate would satisfy a breadth test it has not met, while an estate spanning storage and load balancing would fail one it had.
Minimum population
At least five distinct applicable resources, counted per family.
Not assessed when
No resilience evidence was collected, the evidence contained no measurable signals, only one governance concern was observable, or the population was below the minimum.
In every case the observed signals are still printed with their denominators, so a reader sees what was measured even when no rating was issued.
