Risk
Materiality rules M0 to M6
The seven named rules that assign a materiality band, published with identifiers so any band in a pack can be checked against its cause.
Currentengine 9.0.0Verified 2026-08-30
Every band a pack prints carries the identifiers of the rules that produced it. These are those rules.
| Rule | What it does |
|---|---|
| M0 | A control the mapping declares as governing the account as a whole is estate-wide, whatever its resource count |
| M1 | Estate-wide when 10 or more distinct resources failed, or when it failed in every region it was evaluated in |
| M2 | Broad when 2 or more distinct resources failed, or failures span more than one region |
| M3 | Contained when exactly one distinct resource failed |
| M4 | Not determinable when the evidence carried no resource identifier. Reach is not guessed at, and the control is still reported in full |
| M5 | One band higher, capped at estate-wide, when the control is critical and the mapping records the concern as externally reachable and the control as preventive |
| M6 | A detective control is never escalated by severity |
Why M0 comes first
Root-account and organisation-wide controls fail on one nominal resource and reach everything in the account. Ordering by resource count alone would band the most consequential failures as contained.
Why M6 exists
A missing alarm is a visibility gap, not an open door. Escalating detective controls by severity would inflate the band exactly where it needs to discriminate.
What none of them do
None reads revenue, data value, workload criticality, regulatory position or probability of compromise. The assessment observes none of those.
