How your account security is rated
What the 0-to-100 score means, and how serious each type of finding that can show up on your dashboard is.
The security score
The score starts at 100 and goes down as open findings appear in your account. Each finding subtracts points according to how serious it is — a critical one weighs far more than a high one, and a high one weighs more than a medium one.
The subtraction is not linear: adding a second or third finding of the same severity does not take off as much as the first one did. This is deliberate, so that an account with many findings of the same type does not fall to 0 artificially — the score keeps reflecting the real difference between an account with few problems and one with many, instead of flattening out as soon as it passes a certain count.
Only findings that represent a real security risk count towards the score. Operational information that also appears on your dashboard — such as a service quota about to run out, or an active alarm — does not subtract points, even though it is worth reviewing.
Rating of each type of finding
The severity of each finding is based on the AWS Security Hub standards (Foundational Security Best Practices) and the CIS AWS Foundations Benchmark, the same criteria AWS uses internally to classify its own security controls.
| Type of finding | Rating |
|---|---|
| Root account without multi-factor authentication (MFA) | Critical |
| S3 bucket with public read or write access enabled | Critical |
| Security group with all ports open to the internet | Critical |
| Security group with a database port open to the internet (MySQL, PostgreSQL, SQL Server, MongoDB) | Critical |
| Resource reachable from outside the account and publicly exposed | Critical |
| S3 bucket without full public access block (not yet exposed) | High |
| Security group with remote access (SSH/RDP) open to the internet | High |
| Account with no active CloudTrail trail, or one that stopped recording | High |
| Resource shared with a specific external account (not public) | High |
| Backup job failed in the last 7 days | High |
| IAM user without multi-factor authentication (MFA) | Medium |
| Account without its own password policy, or with an incomplete one | Medium |
| Access key not rotated in more than 90 days | Medium |
| User with console access enabled, unused for more than 90 days | Medium |
| S3 bucket without account-level public access block | Medium |
| S3 bucket without default encryption configured | Medium |
| Unencrypted EBS volume or RDS instance | Medium |
| CloudTrail active but not configured across all regions | Medium |
| IAM role with granted permissions that are never used | Medium |
| Customer-managed KMS key without automatic rotation | Medium |
| Secret in Secrets Manager without automatic rotation | Medium |
| Backup plan with no resources selected | Medium |
| Findings from GuardDuty, Security Hub, Inspector, Macie, AWS Config and Trusted Advisor | Per each AWS service own classification |
Is some rating unclear, or do you think something should be reviewed? Write to us through soporte.valion.com.co.