You have associated a public policy with a scope, implemented security measures, and yet the compliance score for certain requirements remains stuck at 0%, with nothing you do moving it. This is not an anomaly: it is a sign that the requirement in question has no security measure mapped to it in the public catalog. This article is aimed at CISOs and pilots who encounter this situation, to understand why it occurs and which levers to activate.
Why a public policy requirement may have no mapped measure
A public policy is a security framework (ISO 27001, NIS2, or any other framework in the Tenacy catalog) made available with its requirements already broken down. For each of these requirements, the catalog generally offers one or more security measures, called suggested measures, intended to help satisfy it.
However, this correspondence between requirements and suggested measures is not 100% guaranteed for two main reasons: some requirements are organizational or procedural in nature (for example, formalizing a governance structure or designating a responsible person) and do not naturally translate into a single technical measure, and the mapping of a complete framework remains an ongoing effort that may not yet cover every requirement at the time you use it.
The direct impact on the compliance score
The absence of mapping is not without consequence for two of the three types of compliance score that Tenacy can calculate for a policy.
Coverage score: this measures, for each applicable requirement, the contribution made by the measures benefiting the scope and associated with that requirement. If a requirement has no associated measure, its coverage score is 0%, regardless of the actual state of compliance on the ground.
Measured score: this is based on the same principle as the coverage score, adding the effectiveness and operational performance of the measures. Without a mapped measure, there is nothing to measure: the requirement's contribution is therefore also zero.
Declarative score: conversely, this is not built from measures but from responses submitted through assessments or campaigns directly targeting the requirement. An unmapped requirement can therefore achieve a perfectly normal declarative score, as long as an assessment has been submitted for it.
Concretely, if a policy has two requirements of equal priority — one covered 100% by measures and the other with no mapped measure — the policy's coverage score will show 50%, the weighted average of the two, even if the unmapped requirement is otherwise perfectly met in practice.
The available lever for handling an unmapped requirement
The only available lever is to create a private policy derived from the public policy. Several options are available to you, depending on the level of precision you wish to retain for the rest of the policy.
Map the requirements with no measures: a derived policy carries over the requirements and mapping from the public framework while allowing you to add your own customizations — in particular, a security measure specific to your organization that you associate yourself with the uncovered requirement.
Add the Applicability priority scale to the requirement: after deriving the public policy, configure this policy with the Applicability priority scale. If the unmapped requirement is not relevant to your context, you can set the priority to not applicable to exclude it from the score calculation. Also remember, when assigning scopes to the policy, to configure the Applicable priority.
⚠️ The downside of creating a private policy derived from a public policy is that the derived policy does not inherit updates made to the original public policy.
