Defining the SPR threshold
To define your organizational security posture threshold:
Go to Settings > Risk.
Set the threshold (an atomic risk score).
Click Save.
Note: Only assets with (atomic) risk scores below this threshold exclusively will be complying with your security posture policy.
Any asset with a risk score smaller than the configured threshold (80 in the example above) will be considered secure (below your risk threshold). This means that a vulnerability-free asset with a risk score above 69 will be considered secure (compliant). However, an asset with at least a single vulnerability and a risk score of 80 will be non-compliant.
SPR per Business Group
To measure progress across Business Groups and see which have more risk than the others, Vulcan Cyber ExposureOS automatically calculates the SPR per Business Group and presents its relative SPR compliancy. The same applies to the SPR of the entire organization.
The SPR per Business Group is visible on the Vulnerabilities page and the Home Page Dashboard.