VALION VALION
Language English
Security

How your account security is rated

What the 0-to-100 score means, and how serious each type of finding that can show up on your dashboard is.

The security score

The score starts at 100 and goes down as open findings appear in your account. Each finding subtracts points according to how serious it is — a critical one weighs far more than a high one, and a high one weighs more than a medium one.

The subtraction is not linear: adding a second or third finding of the same severity does not take off as much as the first one did. This is deliberate, so that an account with many findings of the same type does not fall to 0 artificially — the score keeps reflecting the real difference between an account with few problems and one with many, instead of flattening out as soon as it passes a certain count.

Only findings that represent a real security risk count towards the score. Operational information that also appears on your dashboard — such as a service quota about to run out, or an active alarm — does not subtract points, even though it is worth reviewing.

Rating of each type of finding

The severity of each finding is based on the AWS Security Hub standards (Foundational Security Best Practices) and the CIS AWS Foundations Benchmark, the same criteria AWS uses internally to classify its own security controls.

Type of findingRating
Root account without multi-factor authentication (MFA)Critical
S3 bucket with public read or write access enabledCritical
Security group with all ports open to the internetCritical
Security group with a database port open to the internet (MySQL, PostgreSQL, SQL Server, MongoDB)Critical
Resource reachable from outside the account and publicly exposedCritical
S3 bucket without full public access block (not yet exposed)High
Security group with remote access (SSH/RDP) open to the internetHigh
Account with no active CloudTrail trail, or one that stopped recordingHigh
Resource shared with a specific external account (not public)High
Backup job failed in the last 7 daysHigh
IAM user without multi-factor authentication (MFA)Medium
Account without its own password policy, or with an incomplete oneMedium
Access key not rotated in more than 90 daysMedium
User with console access enabled, unused for more than 90 daysMedium
S3 bucket without account-level public access blockMedium
S3 bucket without default encryption configuredMedium
Unencrypted EBS volume or RDS instanceMedium
CloudTrail active but not configured across all regionsMedium
IAM role with granted permissions that are never usedMedium
Customer-managed KMS key without automatic rotationMedium
Secret in Secrets Manager without automatic rotationMedium
Backup plan with no resources selectedMedium
Findings from GuardDuty, Security Hub, Inspector, Macie, AWS Config and Trusted AdvisorPer each AWS service own classification

Is some rating unclear, or do you think something should be reviewed? Write to us through soporte.valion.com.co.