On a perimeter or a policy, Tenacy can display three types of compliance score: declarative, coverage, or measured. These are not three different indicators to add together, but three different ways of calculating the same thing, with an increasing level of reliability. This article explains what each one actually measures, and above all how to read them together without making mistakes.
The common principle: a compliance score, for a policy and a perimeter
All three scores answer the same question: to what extent does a perimeter comply with a given security policy? What changes is the data source used to answer it: an answer declared by a human, the presence of security measures, or the actual performance of those measures.
The declarative score: based on assessment responses
The declarative score is the average of the latest responses submitted for each applicable requirement of the policy, weighted by the priority of those requirements.
🔎 This is the only compliance score available for supplier and application type perimeters: these perimeter types do not benefit from security measures, so neither the coverage score nor the measured score can apply.
⚠️ The declarative score visible in the Policies module reflects the score from the last validated campaign on this policy for a perimeter. All requirements declared as not applicable in the assessment campaign have no score carried over into the Policies module and therefore have no impact on the declarative score.
The coverage score: based on measures linked to requirements
The coverage score is the average of the coverage rates of applicable requirements, weighted by their priority and effectiveness. The coverage rate of a requirement corresponds to the sum of the coverage contributions of the measures benefiting the perimeter and associated with that requirement (generally capped at 100%).
For example:
A requirement with one linked implemented measure at 100% effectiveness has a coverage score of 100%.
A requirement linked to an implemented measure with an effectiveness rate of 80% has a coverage score of 80%.
A requirement linked to a non-implemented measure has a coverage score of 0% until the measure is implemented.
🚫 If a requirement has no associated measure in the catalog, its coverage score is 0%, regardless of the actual state of compliance on the ground. This article details this situation and the available levers.
⚠️ If a requirement is declared as not applicable in an assessment campaign for a perimeter, the coverage score and the measured score will show the requirement without a score. We infer that if it is not applicable from an assessment campaign, this should have an impact on the other scores. Currently, there is no other way to make a requirement not applicable than through this method.
The measured score: based on the actual performance of measures
The measured score follows the same principle as the coverage score, adding the actual operational performance of the measures.
The operational performance of a measure depends on the recurring tasks and performance indicators associated with it:
If no recurring task or performance indicator is associated with the measure, a default operational performance value is used (75% unless configured differently).
If a recurring task or indicator exists but no period has yet elapsed, the same default value is used while waiting for data.
Otherwise, it is calculated from the average completion rate of recurring tasks and/or the achievement of performance indicators over the relevant period.
Frequently asked questions
Which type of score applies to supplier or application type perimeters? Only the declarative score: it is the only type of score available for these perimeter types, which do not benefit from security measures.
Does the declarative score count requirements with no submitted response as 0%? No, they are ignored in the calculation rather than counted as 0%, which makes the declarative score inherently partial as long as not all applicable requirements have a submitted response.
What is the difference between the coverage score and the measured score if the measures in place are the same? The coverage score only looks at the declared coverage rate of the measures (and their effectiveness). The measured score goes further by incorporating the actual operational performance of those measures, calculated from the associated recurring tasks and indicators. Two perimeters with the same measures in place can therefore have an identical coverage score but a different measured score.
