The four variables
Evidence, confidence, and what 'unknown' means
The fourth variable: how confident the evidence is behind the other three answers, and how to treat what is genuinely unknown.
4 min read
What you'll be able to do
- Explain why evidence confidence is treated as its own variable rather than folded into the others.
- Distinguish a confirmed answer from an inferred one and from a genuinely unknown one.
- State the safer default when confidence is low.
The first three variables each produced an answer: a lifetime, a harvestability judgment, a protecting mechanism. The fourth variable asks how much to trust each of those answers. A confirmed observation, a reasonable inference, and a guess are not the same thing, even when they happen to point to the same conclusion.
- Confirmed — observed directly: a captured handshake trace, a verified backup retention policy, a data classification signed off by the data owner.
- Inferred — reasoned from adjacent evidence: a service is assumed to use its platform default TLS configuration because no override was found in its configuration.
- Unknown — no evidence either way. This is a legitimate answer, not a gap to paper over with an assumption.
This is also why a Mosca-style verdict, covered next, should always be dated and labeled with its confidence level rather than presented as settled fact. Confidence can change — a configuration gets confirmed, a vendor answers a questionnaire — without anything about the underlying data changing at all.
RelixQ's QAST scores exposure across exactly these four variables — data confidentiality lifetime, harvestability, the reachability of the protecting cryptography, and evidence confidence — for the same reason this course treats them separately: collapsing them into one number too early hides which one is actually driving the result.
With all four variables defined, the next module turns them into a decision: when does a given exposure become urgent enough to act on.
Marking a lesson complete only updates this browser.