A customer's contract cites your hardening benchmark percentage — should you re-rank the standard's items?
answer
- the value is that you did not choose it
- forking means owning it forever
- two numbers, different jobs
- subset never chosen by the doers
- non-applicable needs a name attached
basics
~20 sKeep the published list untouched as the outward number and add an internal load-bearing subset that drives engineering priority. Re-ranking the standard itself destroys the only property the number had — that you did not choose the weights — and leaves nobody able to compare you with anyone.
solid answer
~60 sI would not re-rank the published list. Its entire value to the customer is that we did not choose it: two organisations quoting the same items mean the same settings, and a weighted score means only that we scored ourselves against our own list. Forking the content also makes us the maintainer of a standard across every platform release, which is real ongoing cost for a document we get for free. What I would do instead is publish an internal load-bearing subset — a dozen or so items whose failure actually removes something an adversary depends on in our estate — track it at 100% with its own owner, and report both numbers, so a green outward percentage can never hide a red inner one. The people who must do the work should not be the ones who decide which items count, and if the contract demands 100% including items irrelevant to a control plane we do not operate, that is a scope conversation with the customer, not something to manufacture.
go deeper
Understand that the percentage is used outside the company, so changing how it is calculated is not a purely technical choice — someone is comparing your figure with other organisations'.
Be able to explain why a self-chosen weighting makes the number unreadable to an outsider and why forking a published standard creates maintenance work that lasts as long as the platform does.
Show the two-number arrangement in practice: which items are in your load-bearing subset, why those, and the rule that the outward figure is never reported without the subset's condition beside it.
Own the governance and the conversations — who picks the subset and who may not, who signs a non-applicable item, what you tell a customer whose contract demands conformance on items that mean nothing in your estate, and what you say when leadership asks for a rounder number.
## The decision Somebody outside your organisation is consuming a number: a customer's contract, an insurer's questionnaire, a leadership dashboard. Internally you know the number is an unweighted count over a list written for every reader of the platform, and that a dozen of its items carry nearly everything an adversary would care about in your estate. The tempting move is to re-weight the list so the number tracks reality. This question is about why that is usually the wrong call, and what to do instead. ## Why re-ranking the published list destroys its value - **The number's meaning is external.** "We follow this published standard" is a statement the reader can check against other organisations, other years and their own environment. "We follow this published standard, re-weighted by us" is a statement about your opinion, and the reader has no way to price it. In the worst reading it looks like the weights were chosen after seeing which items failed. - **You inherit maintenance.** Published standards are revised as the platform changes: items are added, split, retired. A fork must be reconciled with every revision by somebody in your organisation, forever, for a document that currently costs you nothing. - **You lose the year-over-year line.** A re-weighted score is not comparable with last year's score under the old weights, so the one thing the number was reliably good for — drift — goes away too. - **It solves the wrong problem.** The defect is that nobody sorted the failing items, and a weighting scheme hides that rather than fixing it: the same argument about which items matter now happens once, in private, and is then frozen into arithmetic nobody re-examines. ## What to do instead Run two numbers with different jobs. 1. **The published percentage, unmodified**, for the outside. It is comparable, it is cheap, and it detects drift. Report it as what it is: agreement with a broadly applicable settings list. 2. **A named load-bearing subset**, for the inside. A short, explicit list — for a Kubernetes estate, the node agent's authentication and authorization path, the scope granted to workload identities, whether credentials handed to workloads are short-lived and bound, and whether the admission path will accept a workload asking for the host filesystem or host namespaces. Track this at 100%, item by item, with an owner. A failure here is an incident-shaped conversation; a failure in the wider list is a backlog item. The rule that keeps this honest: **the outward number may never be reported without the subset's condition next to it.** The whole reason organisations drift into scoring games is that a single flattering number travels further than a nuanced one. ## The organisational parts, which are the actual content of this question - **Who chooses the subset.** Not the platform teams who must do the work — that is marking your own homework in the direction of less work. Not the outside standard's author, who does not know your estate. In practice a small group that includes whoever owns the adversary picture, with the subset published so anybody can argue with it. - **Who may declare an item non-applicable.** "We do not operate that control plane" is a legitimate and common statement, and it is also the easiest sentence in the world to abuse. It needs a named person and a written reason, and it needs to be revisited when the estate changes — an organisation that starts running its own nodes has just made a hundred dormant items live. - **What you tell the customer when the contract demands 100%.** The honest answer is that some items govern components you do not run and settings that do not exist in your distribution, and that you will commit to the load-bearing subset at 100% plus the published percentage as-measured. That is a negotiation with a stated reason. Manufacturing conformance on items that mean nothing in your estate costs real engineering time and buys the customer nothing they wanted. - **What happens when leadership asks for the number to go up.** Say what a point costs and what it removes. If the next eight points are naming conventions on a component you do not run, that is a quarter spent on a rounder figure — and if the load-bearing subset is not at 100%, the same quarter has an obvious better home. ## The judgment being tested An interviewer is checking whether you can hold two truths at once: the published number is a poor proxy for exposure **and** it is worth keeping exactly as published. Candidates who only see the first want to redesign the standard; candidates who only see the second defend the percentage as if it meant something. The lead's answer keeps the outside number outside, builds the honest list inside, and makes sure neither one can be quoted without the other.
- What stops the internal load-bearing subset from quietly shrinking?Publish it, attach a named owner to each item, and require the same person who signs off a removal to say what an adversary regains. Also revisit it when the estate changes shape — a team that starts operating its own nodes has just made a set of dormant items live, and a subset written for a managed control plane silently stops covering them.
- Is there any case where you would genuinely fork the published list?When the platform you run has diverged far enough that most items do not apply — a heavily customised distribution, or an internal platform the standard was never written for. Then you are not re-weighting, you are writing your own standard, and you should say so plainly rather than reporting a percentage against a document that no longer describes what you run.
- The customer only wants one number. Which one do you give them?The published percentage, because it is the one they can compare, plus one sentence that the load-bearing subset is at 100% or is not. If the subset is red, that sentence is the more important half of the answer and withholding it is the thing you will regret when they find out from somewhere else.
saying these in an interview costs you the question
- Re-weights the published list and still calls it that standard
- Lets the teams doing the work choose which items count
- Reports the outward percentage with nothing beside it
- Spends a quarter raising a score with no load-bearing failures
- Treats non-applicable as a decision needing no owner