Trust TRU-010

Grading methodology

Grading keeps verified control evidence, attributed pressure and evidence quality separate. Shared infrastructure, candidate volume and missing evidence do not become simplistic risk points.

Bounded, non-exploitative Authorised external assessment.

Bounded evidence. Explicit responsibility. No hidden inference.

The useful answer

Grading methodology explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals.

Grading methodology explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals. Grading keeps verified control evidence, attributed pressure and evidence quality separate. Shared infrastructure, candidate volume and missing evidence do not become simplistic risk points.

Route-specific context

The decision this page is designed to support

01
Review audience
Security reviewer, board adviser
02
Control objective
Audit how the Overall Signals Grade is formed. Grading methodology explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals.
03
Proof boundary
The exact target, source, observation time, responsibility and evidence state remain available to entitled readers. Evidence basis: Candidate contract.

Grade policy v11

Precision only when the evidence earns it

A+95–100

Exceptional governed external posture, subject to strict coverage, confidence and safety conditions.

A / A-85–94.99

Strong externally observed controls with limited material pressure.

B+, B, B-70–84.99

Established protections with meaningful, prioritised improvement work.

C+, C, C-55–69.99

Mixed evidence: some controls are supported and material action remains.

D+, D, D-40–54.99

Weak governed external posture requiring focused remediation or validation.

E0–39.99

Material deficiencies or safety floors dominate the supported evidence.

INo score

Evidence is insufficient for a defensible grade.

A deliberate path

From permission to retained evidence

  1. 01

    Review the governed control described by grading methodology.

  2. 02

    Trace each statement to its stated evidence basis, owner and review date.

  3. 03

    Carry the published limitation into procurement, assurance or technical interpretation rather than treating silence as approval.

Evidence before assertion

What the product can support

Every governed capability ends with an explicit disposition. Current observations can support a strength or an action; missing, stale or unavailable evidence remains an unknown and cannot become reassurance. The exact target, source, observation time, responsibility and evidence state remain available to entitled readers.

Binding boundary

Candidate associations are not confirmed vulnerabilities and require target applicability validation.

Candidate contract

Binding boundary

Shared or provider-managed infrastructure is dependency context and is not automatically customer exposure.

Responsibility and attribution contract

Binding boundary

Missing, stale, disputed or unavailable evidence cannot be treated as safety.

Capability reconciliation contract

Binding boundary

Provider or collector failure cannot improve a grade.

Grade guard and capability tests

Binding boundary

The Overall Signals Grade covers governed externally assessable evidence, not the organisation's complete security or breach likelihood.

Grade policy v11

Direct answers

Questions a careful reader should ask

What does Grading methodology establish?

Grading methodology explains the control, evidence and limitation a reviewer should use when evaluating Domain Signals. It establishes only what the governed evidence supports.

What does it not establish?

It does not prove complete organisational security, exploitability, breach likelihood or the absence of unobserved weaknesses.

How can I verify the conclusion?

Use the linked evidence or capability record to inspect source, observation time, target, responsibility and the condition required for closure.