What is our security score?

The business question What is our security score? provides a high level overview of the application risk assessment. It helps identify the most critical applications based on their CIA score ( Confidentiality, Integrity, Availability) in the application portfolio. This business question helps your enterprise comply with regulations by identifying yet-to-be assessed applications so that you can initiate activites to capture the required compliance data .

The license package IT Transformation Server - Enterprise is required to work with this business question.

The business question shows a bar chart and data set showing risk assessment of applications:

  • The Application CIA Rating Distribution chart shows number of applications according to their values Essential, Critical, and Not Critical for the following indicators:
    • Confidentiality: The level of criticality that the application prevents unauthorized access to sensitive information.
    • Integrity: The level of criticality that the application data is authentic and trustworthy.
    • Availability: The level of criticality that the application is consistently and readily accessible for authorized parties.
  • Point to a bar to view a tooltip with the indicator name, number of applications, and indicator value. Click a bar to open an Application Security Score data workbench showing the applications repesented by the bar. You can edit the values for the Confidentiality, Integrity, Availability indicators.
  • The Application Security Score data set lists all applications and their CIA scores. Review and edit thhe values for the Confidentiality, Integrity, Availability indicators.

Applications must be in the repository and well-documented. For each application, the indicators Confidentiality, Integrity, Availability should be defined to have meaningful data this business question.

Go to the Data Quality page and resolve the issues to ensure that the data is complete.

Go to the Data Source page to review the applications that are used to answer the business question. The data source is a list report and cannot be edited.