Assessment Methodology

Scope: account and regions

Every enabled region in one AWS account is scanned by default. Narrowing the scope is an exception, and the pack states what was covered.

Currentengine 9.0.0Verified 2026-08-30

The default is everything

Control checks run across every enabled region in the account. The regions input on the assessment exists to restrict scope where an engagement explicitly requires it, not to enable it.

Collectors that enumerate resources do the same: the resilience and cost collectors discover enabled regions and fan out across them.

One account

One AWS account per engagement. There is no organisation-wide scan, no cross-account traversal and no portfolio rollup. The role can only be assumed in the account it was created in.

Account metadata records whether the account is a member of an organisation and whether it is the management account, but that is context for the reader, not an extension of scope.

What the pack states

Every board pack prints the scan scope: the account it covered, the regions, and a note that the assessment was read-only and made no production change. A reader can see what was in scope without asking.

Global versus regional

One region is nominated as the home region for calls that are global rather than regional, and for reading Security Hub posture. It does not limit the scan.