Security Score
The Security Score is the headline metric on your Cert-IX dashboard. It rolls up signals the platform already collects about your organization — open vulnerability findings, compliance progress, and asset and configuration hardening — into a single number on a 0–100 scale, so you can see where you stand at a glance and tell whether your posture is improving over time.
The score is a derived rollup, not a raw count. A handful of Critical findings weighs far more heavily than a long list of Low-severity ones, so a lower count does not automatically mean a higher score. The figure you see reflects only your own tenant's data — Cert-IX does not score you against other customers.
How the score works
A few properties are worth understanding before you read too much into the number:
- It is a weighted rollup. Individual findings and posture signals are combined and weighted by severity and impact rather than counted equally. The exact weighting is maintained by the platform and refined over time, so treat the categories below as relative contributors rather than fixed percentages.
- It is tenant-scoped. The score is computed from your organization's assets, scan results, and compliance data, and what each user sees is further constrained by their role-based permissions.
- It updates as new data arrives. As fresh scan results, scanner-agent telemetry, and compliance changes flow in, the score is recomputed to reflect your current state rather than a point-in-time snapshot.
Rating bands
Use the following bands as a guide to interpret the number. They describe posture in plain language rather than acting as hard pass/fail thresholds:
| Score | Rating | What it generally indicates |
|---|---|---|
| 90–100 | Excellent | Strong posture; few open risks of consequence |
| 70–89 | Good | Solid foundation with minor gaps to close |
| 50–69 | Fair | Noticeable gaps; remediation recommended |
| 30–49 | Poor | Significant open vulnerabilities present |
| 0–29 | Critical | Urgent issues that warrant immediate attention |
What feeds the score
The score draws on the same data the rest of the platform already surfaces. Rather than a fixed formula, think of it as a blend of a few primary contributors and some supporting posture signals.
Primary contributors
Open vulnerability findings. The largest influence on the score is your outstanding vulnerabilities, weighted by severity. Findings are ranked Critical / High / Medium / Low, and the distribution — not just the count — moves the number. These findings come from the same pipeline that powers Vulnerability Management: the Scan API's engines, CVE-based detection from the Bitscanner agent, and dependency checks. Resolving Critical and High items is the fastest way to raise the score.
Compliance posture. Your progress against the frameworks you are tracking in Compliance also contributes. Because Compliance is a Beta capability, its influence on the overall score may evolve as that module matures.
Supporting signals
Beyond the two contributors above, the score reflects general hardening of your environment, including:
- Asset and configuration hardening — the configuration and compliance-hardening posture reported by scanner agents such as Bitenforcer, which evaluates against CIS, STIG, and PCI-DSS baselines. See Scanner Agents.
- Identity and access controls — the account-security controls Cert-IX offers, including multi-factor authentication (TOTP and WebAuthn/FIDO2) and role-based access control.
Compliance tracking is currently in Beta. As frameworks, evidence, and control coverage expand, how strongly compliance progress weighs into the overall score may change.
Tracking your score over time
The dashboard keeps a running history of your Security Score so you can see the direction of travel, not just today's value. Reviewing the trend after a scan or a remediation sprint tells you whether the work is actually moving the needle, and a sudden drop is a useful prompt to check what changed — for example, a new Critical finding surfaced by a recent scan.
Improving your score
Because the score is driven by real findings and posture data, the way to raise it is to close real gaps. The highest-leverage actions are:
| Action | Why it helps | Where to do it |
|---|---|---|
| Remediate Critical and High vulnerabilities | Severity-weighted findings are the biggest single driver | Vulnerability Management |
| Harden asset and system configurations | Closes CIS/STIG/PCI-DSS baseline gaps reported by agents | Scanner Agents |
| Enable MFA and tighten access | Strengthens identity controls across accounts | Account and organization settings |
| Progress your compliance frameworks | Improves your tracked compliance posture | Compliance |
The score reflects your latest data. After remediating findings or hardening a system, run a fresh scan so the improvement is picked up and the score is recomputed.
Learn more
- Dashboard Overview — how the score fits alongside the rest of your dashboard
- Vulnerability Management — where the finding data behind the score lives
- Compliance Overview — track frameworks and improve your compliance posture (Beta)
- Scanner Agents — deploy agents that feed asset, vulnerability, and hardening data
Cette page vous a-t-elle été utile ?