Board Pack
How to read the Evidence Register
Working through the register row by row, what each column supports, and how to turn a row into a closed finding.
The board pack states a position. The Evidence Register is where an engineering team works.
Reading a row
| Read | To answer |
|---|---|
| Control title and severity | What is being asserted, and how seriously the scanner rates it |
| Failing and evaluated resource counts | How much of the estate this covers, not just that it failed |
| Failing resource identifiers, and regions | Exactly what to open |
| Governance implication | Why this matters, in terms you can take to a stakeholder |
| First action | Where to start |
| Closure evidence | What would demonstrate it is done |
Start with reach, not order
The register is ranked, but ranking is not a work order. A contained finding on a production resource may matter more to you than a broad one across development accounts, and the assessment cannot know which is which.
Use the failing resource count and regions to decide.
The denominator matters
A control failing on 3 of 4 resources is a different situation from one failing on 3 of 300. Both appear as failed controls; only the evaluated count distinguishes them.
When the identifier list is truncated
A bounded number of resource identifiers is tracked per control. The register states explicitly whether the list is complete, so a short list is never mistaken for the whole set.
Closing a finding
Closure evidence describes what would show the control now passes. The honest test is the next assessment: a control that failed before, was evaluated again, and now passes is reported as closed. One that was not evaluated at all is reported as not re-assessed, which is not the same thing. See What changed since the last assessment.
How to obtain it
Produced with every successful assessment, and available on request. See The Evidence Register.
