Security Posture
Pronunciation: sih-KYOOR-ih-tee PAHS-chur
Definition
Security posture is the current overall condition of an organization’s security capabilities, exposure, controls, readiness, and ability to recover. Security posture reflects assets, vulnerabilities, identities, configurations, threats, controls, monitoring, response, recovery, governance, and third-party dependencies. It is an evolving state rather than a single certification, product, or score. Posture can appear strong while hidden assets, stale inventories, accepted exceptions, vendor concentration, or untested recovery create material weakness.
Overview
Security posture reflects assets, vulnerabilities, identities, configurations, threats, controls, monitoring, response, recovery, governance, and third-party dependencies. It is an evolving state rather than a single certification, product, or score.
Posture can appear strong while hidden assets, stale inventories, accepted exceptions, vendor concentration, or untested recovery create material weakness. Metrics based only on detected findings may reward organizations that look less carefully.
Assessment should combine control evidence, incidents, attack-surface data, testing, threat intelligence, resilience exercises, and business impact. Leadership needs trends, uncertainty, ownership, and priority actions, while major changes trigger reassessment rather than waiting for a periodic report. Posture reporting should distinguish verified control evidence from assumptions and self-reported claims.
Security posture is the current overall condition of an organization’s security capabilities, exposure, controls, readiness, and ability to recover. Security posture is a changing, evidence-based view of exposure and readiness that must include hidden dependencies, recovery, and measurement uncertainty.
A production treatment of Security Posture should test the current overall condition of an organization’s security capabilities, exposure, controls, readiness, and ability to recover within the relevant asset, decision, or service state. The Security Posture context record for exposure, controls, and readiness should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Security Posture should determine whether safeguards addressing exposure, controls, and readiness changed exposure in practice, not merely whether a document or setting existed.
Quality review for Security Posture should sample real cases involving exposure, controls, and readiness, compare expected and actual outcomes, and track unresolved exceptions until remediation is independently verified.
Key Takeaway
Security posture is a changing, evidence-based view of exposure and readiness that must include hidden dependencies, recovery, and measurement uncertainty.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)