Argus Omni Whitepaper 02 / Version 1.0

Authorization-first assessment and the Argus Ready score

A transparent method for turning an agreed security scope and verified evidence into a useful 1-10 posture view without confusing public prospect data, technical severity, compliance, and business risk.

Executive summary

A security score is useful only if a reader can answer five questions: What was in scope? When was it assessed? Which evidence supports it? How was it calculated? What important uncertainty remains?

Argus Ready separates commercial qualification from security assessment. Public business records and historical observations may help identify an organization that could benefit from a conversation. They cannot support a claim that the organization is vulnerable, breached, noncompliant, or unsafe. The customer-facing 1-10 score exists only after written authorization and evidence collection inside the agreed boundary.

The current score uses five required dimensions:

  1. External exposure.
  2. Identity and access.
  3. Data protection.
  4. Patch and configuration.
  5. Detection and response.

Each dimension is assessed from 0 to 100. Missing dimensions cause scoring to fail. The mean is mapped to 1.0 through 10.0, then explicit penalties are applied for confirmed critical and high findings. The model version, dimension values, penalty counts, reasons, assessment time, evidence-store reference, and authorization record are stored with the result.

1. The authorization boundary

NIST SP 800-115 describes planning, conducting, analyzing, and using technical security tests and assessments. Argus turns planning into a hard product boundary. An engagement cannot proceed without:

  • A named legal entity and authorizing person.
  • A content digest of the signed agreement.
  • A non-empty structured scope identifying targets and exclusions.
  • Explicit start and end times.
  • Active status and rules of engagement.
  • An engagement identity that matches the authorized customer.

The gate is not satisfied by an email conversation, form submission, public asset, salesperson's note, or payment. It rejects expired, revoked, empty, or mismatched authorization records.

1.1 Rules of engagement

The rules define permitted techniques, identities and test accounts, source addresses, request limits, maintenance windows, fragile systems, data handling, evidence retention, communication paths, stop conditions, emergency contacts, and procedures for unexpected access.

1.2 Scope changes

New assets or techniques are not absorbed informally. A scope change updates the written authorization, dates, rules, and commercial terms before work crosses the original boundary.

2. Evidence quality

The assessment record distinguishes evidence classes:

  • Provided context: architecture, inventory, policy, or configuration supplied by the customer.
  • Source observation: a bounded collector, scanner, artifact parser, or approved external source.
  • Analyst validation: reviewed behavior or configuration supporting affectedness, reachability, control state, or impact.
  • Reproduction evidence: a controlled demonstration within scope, with exact request, response, artifact, or state transition.
  • Remediation evidence: a verified before-and-after observation after corrective work.

Evidence should identify source, time, target, method, reviewer where appropriate, and a stable reference or digest. Sensitive values are redacted or stored in a separately controlled evidence environment; credentials do not belong in the exposure database or public report.

2.1 Coverage is part of the result

A dimension cannot receive a polished score from missing data. If a required dimension cannot be assessed to the agreed depth, the model refuses the overall score or the report clearly narrows scope. Unknown coverage is not treated as a passing control.

3. The five dimensions

3.1 External exposure

Measures asset visibility, ownership, internet reachability, service minimization, secure edge configuration, external dependencies, and verified remediation of reachable weaknesses. Evidence may include asset and DNS inventory, service configuration, approved observations, certificates, and attack paths.

3.2 Identity and access

Measures identity inventory, privileged access, phishing-resistant authentication, lifecycle, service accounts, conditional access, session control, least privilege, recovery, and review. The focus is whether trust can be established, limited, revoked, and audited.

3.3 Data protection

Measures data classification, collection minimization, access boundaries, encryption and key ownership, backup protection, retention, deletion, leakage controls, and recovery requirements. Controls are evaluated against the data and business process actually in scope.

3.4 Patch and configuration

Measures inventory-to-update linkage, vulnerability prioritization, configuration baselines, exception handling, supported versions, software and device lifecycle, cloud posture, and verification. CISA KEV and EPSS can inform order but do not replace local affectedness and impact.

3.5 Detection and response

Measures useful telemetry, alert coverage, triage, containment authority, incident roles, communication, restoration, exercises, lessons learned, and proof that critical services can recover.

3.6 Evidence bands

BandInterpretationEvidence expectation
0-19Absent, unknown, or materially uncontrolledCritical coverage missing or repeated evidence of unmanaged exposure.
20-39Fragmented and reactiveSome controls exist, but ownership, coverage, or repeatability is weak.
40-59Partially repeatableDocumented controls cover important areas but have material gaps or inconsistent verification.
60-79ManagedDefined ownership, broad implementation, operating evidence, and remediation flow with bounded exceptions.
80-100Verified and resilientStrong coverage, measured operation, tested recovery, timely correction, and few material unresolved paths.

These bands guide assessment judgment. The report must still describe the specific observations behind each dimension; a band label is not evidence.

4. Score model version 1

Each required dimension is a number from 0 through 100. Let D be the arithmetic mean of the five dimension values.

Base score = 1 + (D x 9 / 100)

This maps a mean of 0 to 1.0 and a mean of 100 to 10.0. The model then applies confirmed-finding penalties:

  • 1.0 point for each confirmed critical finding.
  • 0.25 point for each confirmed high finding.
  • Total penalty capped at 4.0 points.
  • Final score floored at 1.0 and rounded to one decimal place.

Only confirmed findings from the authorized evidence store count. Public prospect data and stale historical signals cannot enter this score.

Why an explicit penalty?

Dimension maturity can look healthy while one confirmed path creates urgent material risk. The penalty makes that tension visible. The cap prevents a finding count from erasing all distinction between otherwise different programs; the detailed register still carries every finding.

5. Worked example

Consider an illustrative assessment with these dimension values:

  • External exposure: 75
  • Identity and access: 70
  • Data protection: 80
  • Patch and configuration: 65
  • Detection and response: 60

The mean is 70. The base score is 1 + (70 x 9 / 100) = 7.3. If the assessment confirms one critical and one high finding, the penalty is 1.25. The unrounded result is 6.05, producing a final score of 6.0.

The report would not stop at 6.0. It would show the five values, the penalty, the confirmed conditions, evidence coverage, scope, model version, priority actions, and what a retest could change.

6. Reporting and remediation

The customer package separates audiences while preserving one record:

  • Executive view: scope, score, dimension profile, material attack paths, business impact, and priority decisions.
  • Technical register: affected assets, evidence, reproduction where appropriate, severity, risk factors, remediation, owner, and verification requirement.
  • Coverage statement: sources used, inaccessible areas, exclusions, stale evidence, and assumptions.
  • Remediation plan: immediate containment, near-term correction, architectural work, accepted risk, and target dates.
  • Retest statement: what will be repeated, what constitutes closure, and how the score and risk delta will be recalculated.

A score is dated. Changes after the assessment do not silently rewrite it. A verified reassessment creates a new result and retains the previous model inputs for comparison.

7. Interpretation and limitations

The Argus Ready score is not a certification, warranty, breach prediction, compliance attestation, or substitute for a framework-specific audit. It describes the authorized scope and available evidence at a point in time. Two organizations with different scopes should not compare the number without the dimension and coverage context.

Equal weighting is intentionally simple and reproducible in model version 1. It may not match every organization's risk appetite. A future model could support agreed weights, but any change requires a new version, published formula, migration rule, and side-by-side impact analysis. Historic scores must remain reproducible.

Conclusion

The 1-10 view is a communication layer over an evidence record. Its value comes from the authorization gate, complete required dimensions, transparent formula, explicit finding penalties, scope statement, and verified follow-up. Removing any of those turns a clear score into false precision.

References

  1. National Institute of Standards and Technology, SP 800-115: Technical Guide to Information Security Testing and Assessment, September 2008.
  2. National Institute of Standards and Technology, Cybersecurity Framework 2.0, February 26, 2024.
  3. Cybersecurity and Infrastructure Security Agency, Known Exploited Vulnerabilities Catalog, accessed August 3, 2026.
  4. FIRST EPSS, Frequently Asked Questions and limits of EPSS as a risk input, accessed August 3, 2026.