Skip to main content

AICT scale

info

Administrators only: This page describes a setting reserved for organisation administrators.

The AICT scale defines, for each of the four fundamental security criteria and each level, a description used by the AI to assess the security need of a project during the pre-qualification summary.

Understanding AICT

AICT stands for the four fundamental security criteria on which security needs assessment relies:

  • Availability — capacity of an asset to be accessible and usable by authorised people
  • Integrity — guarantee that the data has not been altered in an unauthorised way
  • Confidentiality — restriction of access to authorised people only
  • Traceability — ability to reconstruct the actions carried out on an asset

Each project is characterised by a level on each of these four axes, which determines its security need profile.

Role of the AICT scale

The AICT scale provides, for each (criterion, level) pair, a textual description that serves as a reference for the AI when generating the pre-qualification summary.

The descriptions configured on this page form the organisation's security need reference set. They allow the AI to align the information collected during pre-qualification (scoping cards, questionnaire, assets) with the right AICT level.

info

The quality of the descriptions entered on this page has a direct effect on the relevance of the AICT levels suggested by the AI for your projects. The more anchored the wording is in your organisation's business context, the more reliable the summaries will be.

Scale structure

For each of the four AICT criteria, the scale has four levels:

LevelGeneral reading
LowLow security need, high tolerance to degradation
MediumModerate security need
HighStrong security need, with notable impact in case of degradation
Very highCritical security need, no tolerance to degradation

Each level is associated with a textual description specifying what this need threshold covers for the criterion concerned.

Example description

For the Availability criterion, Low level:

The resource may experience downtime of more than a day per year, but limited in time.

This kind of wording, supported by a concrete time threshold, gives the AI a tangible benchmark to set the availability level expected of a project.

Modify the scale

From the page, you can:

  • Modify a description — update the wording of a level for a given criterion
  • Align the wording with your organisation's security policy
  • Harmonise the four criteria to guarantee a consistent reading

The changes are taken into account immediately on subsequent AI generations.

Use by the AI

During the pre-qualification summary, the AI consults the AICT scale to:

  1. Analyse the information collected in the scoping cards and the questionnaire
  2. Align these elements with the scale descriptions for each criterion
  3. Suggest an AICT level for each of the project's four axes
  4. Derive the project's overall security need level

These AICT levels are then reused as a reference base for the risk analysis: they condition the identification of feared events and the calibration of impacts.

tip

Write the descriptions using measurable thresholds (downtime, data volume, data sensitivity, etc.). Concrete wording allows the AI to settle on the right level much more stably than a purely qualitative description.