This article aims to provide a comprehensive understanding of the Telivy Internal Security Scan report. The Telivy report offers a detailed assessment of your organization’s security posture and highlighting potential vulnerabilities.

Each security section is divided into 1 or more sub sections. Each subsection has a grade and a weight for the final section grade. The final grade will then be determined as follows:

Final Score = Sum(Section Weight X Section Score)/Sum(Section Weight)

Section score is on a scale from 1 to 4 with 1 being most secure and 4 being least secure. Once the final score is determined, the conversion to a grade score is calculated as follows:

Final Score RangeGrade
4F
3 - 4D
2 - 3C
1 - 2B

Network Security

Network security consists of the following subsections:

  1. Internal Vulnerabilities
  2. External Vulnerabilities
  3. Open Ports
  4. Certificate Security
  5. HTTPs security

Internal Vulnerability

Internal Vulnerability grades will be determined as follows:

CriteriaGrade
>10% of users have a atleast 1 critical Vulnerability4

External Vulnerability

External Vulnerability grades will be determined as follows:

CriteriaGrade
Any High Severity findings4
Any Medium Severity findings3
Only Low Severity findings2
No findings1

Open Ports

Open Ports grades will be determined as follows:

CriteriaGrade
Any High Severity open ports4
Any Medium Severity open ports3
Only Low Severity open ports2
No open ports1

Certificates

Certificate grades will be determined as follows:

CriteriaGrade
Any High Severity certificate findings4
Any Medium Severity certificate findings3
Only Low Severity certificate findings2
No certificate findings1

HTTPs findings

HTTPs grades will be determined as follows:

CriteriaGrade
HTTPs not enabled3
HTTPs enabled1

Weights for Network Security

Internal Vulnerabilities: 10 External Vulnerabilities: 8 Port Scans: 6 Certificate: 4 HTTPs: 8

Data Security

Data Security grades will be determined as follows:

CriteriaGrade
At Least 1 user with data value >= 100,000(OR)Totalrisk>=100,000 (OR) Total risk >= 1,000,000D
Total risk >100,000andlessthan100,000 and less than 1,000,000C
Total risk >10,000andlessthan10,000 and less than 100,000B
Total risk <$10,000A

Dark Web Security

Dark Web grades will be determined as follows:

CriteriaGrade
Dark Web findings in the last 2 yearD
Dark Web findings only prior to last 2 years but newer than 5 yearsC
Dark Web findings prior to 5 yearsB
No Dark Web findingsA

Password Security

Password grade security will be determined as follows:

CriteriaGrade
High number of weak and compromised passwords foundD
Weak and compromised passwords foundC
Few weak or compromised passwords foundB
No Weak or Compromised passwords were foundA