Saltar al contenido principal
Version: Next 🚧

Security Score

The Security Score is the headline metric on your Cert-IX dashboard. It rolls up signals the platform already collects about your organization — open vulnerability findings, compliance progress, and asset and configuration hardening — into a single number on a 0–100 scale, so you can see where you stand at a glance and tell whether your posture is improving over time.

The score is a derived rollup, not a raw count. A handful of Critical findings weighs far more heavily than a long list of Low-severity ones, so a lower count does not automatically mean a higher score. The figure you see reflects only your own tenant's data — Cert-IX does not score you against other customers.

How the score works

A few properties are worth understanding before you read too much into the number:

  • It is a weighted rollup. Individual findings and posture signals are combined and weighted by severity and impact rather than counted equally. The exact weighting is maintained by the platform and refined over time, so treat the categories below as relative contributors rather than fixed percentages.
  • It is tenant-scoped. The score is computed from your organization's assets, scan results, and compliance data, and what each user sees is further constrained by their role-based permissions.
  • It updates as new data arrives. As fresh scan results, scanner-agent telemetry, and compliance changes flow in, the score is recomputed to reflect your current state rather than a point-in-time snapshot.

Rating bands

Use the following bands as a guide to interpret the number. They describe posture in plain language rather than acting as hard pass/fail thresholds:

ScoreRatingWhat it generally indicates
90–100ExcellentStrong posture; few open risks of consequence
70–89GoodSolid foundation with minor gaps to close
50–69FairNoticeable gaps; remediation recommended
30–49PoorSignificant open vulnerabilities present
0–29CriticalUrgent issues that warrant immediate attention

What feeds the score

The score draws on the same data the rest of the platform already surfaces. Rather than a fixed formula, think of it as a blend of a few primary contributors and some supporting posture signals.

Primary contributors

Open vulnerability findings. The largest influence on the score is your outstanding vulnerabilities, weighted by severity. Findings are ranked Critical / High / Medium / Low, and the distribution — not just the count — moves the number. These findings come from the same pipeline that powers Vulnerability Management: the Scan API's engines, CVE-based detection from the Bitscanner agent, and dependency checks. Resolving Critical and High items is the fastest way to raise the score.

Compliance posture. Your progress against the frameworks you are tracking in Compliance also contributes. Because Compliance is a Beta capability, its influence on the overall score may evolve as that module matures.

Supporting signals

Beyond the two contributors above, the score reflects general hardening of your environment, including:

  • Asset and configuration hardening — the configuration and compliance-hardening posture reported by scanner agents such as Bitenforcer, which evaluates against CIS, STIG, and PCI-DSS baselines. See Scanner Agents.
  • Identity and access controls — the account-security controls Cert-IX offers, including multi-factor authentication (TOTP and WebAuthn/FIDO2) and role-based access control.
Beta capability

Compliance tracking is currently in Beta. As frameworks, evidence, and control coverage expand, how strongly compliance progress weighs into the overall score may change.

Tracking your score over time

The dashboard keeps a running history of your Security Score so you can see the direction of travel, not just today's value. Reviewing the trend after a scan or a remediation sprint tells you whether the work is actually moving the needle, and a sudden drop is a useful prompt to check what changed — for example, a new Critical finding surfaced by a recent scan.

Improving your score

Because the score is driven by real findings and posture data, the way to raise it is to close real gaps. The highest-leverage actions are:

ActionWhy it helpsWhere to do it
Remediate Critical and High vulnerabilitiesSeverity-weighted findings are the biggest single driverVulnerability Management
Harden asset and system configurationsCloses CIS/STIG/PCI-DSS baseline gaps reported by agentsScanner Agents
Enable MFA and tighten accessStrengthens identity controls across accountsAccount and organization settings
Progress your compliance frameworksImproves your tracked compliance postureCompliance
Re-scan after you fix

The score reflects your latest data. After remediating findings or hardening a system, run a fresh scan so the improvement is picked up and the score is recomputed.

Learn more

¿Te resultó útil esta página?