A finding in a RedRays product is a statement about one thing that was read from one system at one moment, and every screen and export is arranged so that a reader can tell it apart from a silence.
Security tooling fails quietly in one direction. A false positive is expensive for a day and then dies, because somebody opens it and checks the evidence. A false negative is permanent, because nothing revisits a system that came back clean. Everything below trades a tidier screen for a chance at the second.
Because the finding carries the evidence it was computed from, so somebody who did not run the scan can check the claim rather than take it.
A profile parameter row prints the value the system returned beside the condition that judged it. A segregation of duties finding prints, for each side of the rule, the role or profile that granted the access and the values that matched. A verdict without its evidence has to be believed, and a reader who cannot check the right one cannot dispute the wrong one.
One is a measurement and the other is a silence, and a product that draws them the same way asserts something nobody measured. Every capability has its own version of it.
| Capability | The silence it keeps separate | What that silence is not |
|---|---|---|
| Profile parameters | A parameter the system did not return | Not a safe value |
| Vulnerability assessment | A check skipped for want of a stored logon | Not a clean answer |
| Password strength | A client whose hashes were never read | Not a client without weak passwords |
| ABAP code scanning | A defect class outside the profile that ran | Not a class the code passed |
| BTP assessment | An object whose newest run did not complete | Not an object with nothing wrong |
| Port and service scan | An address that refused or was filtered | Not a closed port |
| Threat modelling | A system that could not be logged on to | Not a system with no path out |
| Segregation of duties | A fact the extract did not carry | Not a fact whose count is zero |
The rule costs something visible: unmeasured parameters get a column of their own, never added to the passes or the failures, and an all-clear is withheld while any object is unresolved.
Because a percentage hides its own denominator, and the denominator is usually the part worth arguing about.
Objects assessed over objects queued makes a reader ask "five of what". Ninety-two per cent answers it in advance, wrongly. Two numbers keep the boundary visible too: a full bar is not a swept tenant, because objects nobody queued are in neither half. See coverage and what was not assessed.
No. A suppressed finding was found, and it stays in the list with the reason it was held back printed on the row.
Suppression is the engine's verdict, taken from a recorded fact: the account is locked, the assignment's validity window does not contain the scan date, the two duties are pinned to organisational values that cannot intersect. A waiver is a person's decision, taken by name. Merging them into one word makes an audit conversation impossible, so they sit in separate columns: a fall in the reportable count beside a rise in the suppressed count is accounts being locked, not conflicts fixed.
Because each is a label somebody typed, and none is what the system checks at the moment that decides the answer.
A role named for customer master data also carries vendor change, because somebody added it years ago and the name did not follow. A published severity is an opinion about a class of issue, not a measurement of your landscape.
The transaction case is the subtlest. A rule condition that accepts any one of several transactions can be satisfied by the display transaction among them, and the sentence the reader takes away then claims more than the person can do. A condition is not a capability. That is a property of rule content, which is why conditions are printed in full and why a rule is measured against a real population first.
It says so, where a number would otherwise have gone.
Honesty about measurement is not completeness. Here is where a person still has to look.
It means it is worth reading. It arrives attached to what was asked, of what, and when, so it can be defended. A clean result with no scope settles nothing.
Read a finding and check it. The condition, the value the system returned, the paths behind an access and the source as it was read are printed, so the claim can be tested against your own system.
From the failure it prevents. A number nobody measured, shown as though it had been, ends an investigation that should have continued, and that is how a landscape stays broken for a year.