This edition publishes the evaluation question and work still required. It contains no scored vendor points.
What must be true
- Required operating systems and response actions are supported.
- A contained device can be safely restored.
- An action is attributable to an authorized responder.
Candidate scope
Two publicly documented offerings form a small pilot. Inclusion is for methodology development, not a claim that these are the only or best choices. Exact tiers and test configurations must be frozen before scoring.
| Offering | Scope | Status |
|---|---|---|
| Microsoft Defender for Endpoint | Plan 2 candidate; device/server entitlements and platform feature differences require confirmation. | Unassessed Capability: null Operating: null |
| Elastic Defend | Endpoint protection integration; exact platform and subscription requirements remain unselected. | Unassessed Capability: null Operating: null |
Evidence still needed
- An agreed device and OS version matrix
- Repeatable endpoint behavior and recovery tests
- Sensor overhead, administration, and licensing evidence
How the evaluation will work
- Fix the workload, organizational assumptions, product editions, and mandatory requirements.
- Publish criterion-specific 0–5 anchors before collecting results.
- Collect reproducible observations, source dates, and operating measurements. Preserve contradictory evidence.
- Use the rubric below without filling unknowns with estimates.
- Have a second reviewer reproduce results. Publish only after both axes reach 80% coverage and critical requirements have explicit results.
| Axis | Criterion | Weight |
|---|---|---|
| capability | Required functions | 40% |
| capability | Representative effectiveness | 30% |
| capability | Evidence and explainability | 15% |
| capability | Required data exchange | 15% |
| operating | Staffing and administration | 30% |
| operating | Environment and deployment | 25% |
| operating | Integration maintenance | 20% |
| operating | Portability and exit | 15% |
| operating | Cost predictability | 10% |
Threshold: 70/100 on each axis. A missing-evidence interval that spans 70 prevents a definitive quadrant label. A critical failure blocks a shortlist recommendation.
Download this research protocol ↓