How We Calculate Your Security Score
Security tools ask for trust; we'd rather show our work. This page documents exactly how answers become scores, and how remediation guidance is produced.
Step 1 · Five-Level Maturity Scale
Every control is answered against a five-level scale. Each level maps to a fixed value between 0 and 1 — there is no hidden scoring.
Controls marked Not Applicable are excluded from scoring entirely — they neither raise nor lower your result.
Step 2 · Importance Weighting
Controls are not all equally important. Each control carries an importance weight reflecting its typical impact on security posture, and each control's own questions carry sub-weights the same way.
A control's score is the weighted average of its question answers. Your domain score is the weighted average of its controls. Your overall score is the weighted average across all applicable controls, expressed as 0–100.
control_score = Σ(question_weight × answer_value) / Σ(question_weight)
domain_score = Σ(control_weight × control_score) / Σ(control_weight)
overall_score = round( Σ(control_weight × control_score) / Σ(control_weight) × 100 )
Step 3 · Score Bands
Excellent
80 – 100
High ISMS maturity. Maintain and continuously improve.
Good
60 – 79
Solid foundation with room to improve. Focus on lower-scoring domains.
Average
40 – 59
Notable deficiencies. Build a remediation plan and start on key controls.
Needs Improvement
0 – 39
Elevated risk. Prioritize a structured remediation project immediately.
How AI Remediation Guidance Is Produced
AI recommendations are grounded in your actual assessment data — control codes, titles, your maturity answers, and their weighting — plus your company context (industry, regulatory environment). The model is instructed to act as a senior information security consultant and produces a structured summary: risk and priority overview, findings, a 30/90/180-day remediation roadmap, organizational responsibilities, and key metrics.
Per-control remediation guidance is generated once per control, stored in a template library, and reused — so the same control always yields consistent advice, reviewable independently of any single report.
What AI doesn't do: invent findings that aren't in your answers, or replace professional judgment. Treat output as expert-drafted starting points, validated by the people who know your systems.
