Skip to content
Calcrivo

Security Hub Score Calculator

Reproduce the AWS Security Hub score: passed controls over enabled controls per standard, averaged, with a severity-weighted view of the failures.

Inputs

controls
controls
controls
controls
controls
controls
controls
controls
controls

Overall Security Score

75.9%

Grade

B — Good

FSBP Standard Score

76.4%

CIS Standard Score

74.6%

PCI DSS Standard Score

76.7%

Failing Controls

83controls

Severity-Weighted Failure Load

165points

Controls per 5 Score Points

18controls

Disabled Control Share

3.3%

Verdict

Critical control failures outrank the headline score — fix those before optimising the percentage

Step by step

  1. Values used

    AWS Foundational Security Best Practices controls enabled = 246 controls; FSBP controls passing = 188 controls; CIS AWS Foundations controls enabled = 59 controls; CIS controls passing = 44 controls; PCI DSS controls enabled = 43 controls; PCI DSS controls passing = 33 controls; Controls disabled across all standards = 12 controls; Failed controls at critical severity = 6 controls; Failed controls at high severity = 21 controls

  2. Security Hub Score

    Standard score = passed controls ÷ enabled controls × 100. Overall score = the arithmetic mean of the enabled standard scores, exactly as Security Hub computes it.

  3. Severity weighting

    Severity-weighted failure load = 10 × critical failures + 5 × high failures — the view the score itself hides, since every control counts equally in the percentage.

  4. Overall Security Score

    = 75.9

  5. Grade

    = B — Good

  6. FSBP Standard Score

    = 76.4

  7. CIS Standard Score

    = 74.6

  8. PCI DSS Standard Score

    = 76.7

  9. Failing Controls

    = 83 controls

How it works

Security Hub averages standard scores rather than pooling controls, so a small standard moves the number as much as a large one — fifteen failures out of 59 CIS controls costs the same as sixty out of 246 FSBP controls. Because every control counts equally within a standard, the severity-weighted load is reported alongside to show which failures actually matter. The Security Hub percentage is what leadership sees on the dashboard, and it can climb steadily while the six critical failures that would end the company sit untouched.

Formulas

Security Hub Score

Standard score = passed controls ÷ enabled controls × 100. Overall score = the arithmetic mean of the enabled standard scores, exactly as Security Hub computes it.

fsbpScore
Passed ÷ enabled FSBP controls × 100
securityScore
Mean of the enabled standard scores
failedControls
Enabled controls not passing across all standards

Severity weighting

Severity-weighted failure load = 10 × critical failures + 5 × high failures — the view the score itself hides, since every control counts equally in the percentage.

criticalFailed
Failed controls whose severity label is CRITICAL
highFailed
Failed controls whose severity label is HIGH

Frequently Asked Questions

How is Security Hub Score calculated?

Standard score = passed controls ÷ enabled controls × 100. Overall score = the arithmetic mean of the enabled standard scores, exactly as Security Hub computes it. Security Hub averages standard scores rather than pooling controls, so a small standard moves the number as much as a large one — fifteen failures out of 59 CIS controls costs the same as sixty out of 246 FSBP controls. Because every control counts equally within a standard, the severity-weighted load is reported alongside to show which failures actually matter.

Why does Security Hub Score matter?

The Security Hub percentage is what leadership sees on the dashboard, and it can climb steadily while the six critical failures that would end the company sit untouched.

What values do I need to enter?

This calculator takes 9 inputs: AWS Foundational Security Best Practices controls enabled, FSBP controls passing, CIS AWS Foundations controls enabled, CIS controls passing, PCI DSS controls enabled, PCI DSS controls passing, Controls disabled across all standards, Failed controls at critical severity, Failed controls at high severity. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why does disabling controls raise my score?

Because the denominator is enabled controls, not applicable controls. Disabling a standard you keep failing is a legitimate scoping decision and also the single easiest way to manufacture improvement, which is why the disabled share is shown here as a first-class number.

Does one control map to one resource?

No. A control is evaluated against every resource in scope and reports pass or fail as an aggregate, so a single failing control can represent one non-compliant bucket or four hundred. Always read the finding count next to the control count before planning the work.

You might also need