Trust Scoring is the calculation of a device’s Trust Level. The calculation takes into account all Trust Factors applied to a device as well as the Trust Effect assigned to each Trust Factor. The result of this evaluated information is a single Trust Level, which describes the device’s overall security posture.
Each Trust Factor applied to a device has an admin-assigned Trust Effect. The Trust Effect determines the impact on a device’s Trust Level when the applied Trust Factor is not satisfied.
In the Trust Scoring calculation, Trust Effects are not weighed equally; the most restrictive Trust Effect takes precedence over all other Trust Effects. The order of Trust Effect restrictiveness (from most restrictive to least restrictive) is as follows:
Always Deny: device is denied access to all Cloud Secure Edge (CSE) services
Low Trust Level: If this factor is not satisfied, the device’s Trust Level will be set to low.
Medium Trust Level: If this factor is not satisfied, the device’s Trust level will be set to medium.
Therefore, the most restrictive Trust Effect of an unsatisfied Trust Factor determines the output of the Trust Scoring calculation.
Example: An admin applies 3 Trust Factors to a device: Firewall, Auto Update, and Disk Encryption. The admin then assigns a Trust Effect to each of these applied Trust Factors, as follows:
Case 1: The device satisfies the requirements of Auto Update and Disk Encryption but does not satisfy Firewall.
Case 2: The device satisfies the requirements of Auto Update, but does not satisfy Disk Encryption and Firewall.