How would you score implemented coverage for one system if two of four evaluative elements were in place?
The Implemented maturity level measures whether a control is operating effectively in practice. Scoring is based on the proportion of evaluative elements in place. In this scenario, two of the four required elements are implemented. This equates to 50% compliance, so the correct score is 50. For example, if a firewall control requires four items (documented rules, change management process, monitoring, and testing), and only two are in place, the organization is halfway compliant. This method ensures that partial implementation is acknowledged but also highlights gaps needing remediation. Scores of 0, 25, or 75 would not accurately reflect two of four elements, making 50 the correct value.
Myrtie
3 days agoJeffrey
8 days agoJaime
14 days agoCurt
19 days agoBulah
24 days agoMagda
29 days agoLeota
1 month agoNickolas
1 month agoGoldie
1 month agoLelia
2 months agoKimberlie
2 months agoRichelle
2 months ago