AWS Access
What the boundary costs in coverage
The read-only guarantee removes three families of scanner check from your assessment. GovIntel publishes which, rather than absorbing it.
A guarantee whose cost is hidden is a marketing claim. This is the cost.
The checks that cannot run
Three families of control check are disabled by the data-plane denials:
- Checks that read CloudWatch Logs event content
- Checks that download and scan Lambda deployment packages for embedded secrets, because retrieving a function returns a pre-signed URL to its source code
- Checks that read S3 object contents or enumerate objects
Those checks are absent from your assessment. They are not reported as passing, and they are not reported as failing. They simply did not run.
The trade GovIntel declines to make
The alternative is to grant the reads so the checks can run. That would mean GovIntel could read the contents of your objects, your log events and your function source.
For an assessment sold on the strength of its access boundary, that is the wrong trade. The narrower claim, that no data-plane content is read at all, is worth more than three families of check.
Also excluded, for a different reason
Low-severity and informational controls are never collected. The scan is invoked at critical, high and medium only. That is a scoping decision rather than a boundary consequence, and it changes the denominator of the security score. See The control contract.
