Board Pack

How to read the Evidence Register

Working through the register row by row, what each column supports, and how to turn a row into a closed finding.

Currentengine 9.0.0Verified 2026-08-30

The board pack states a position. The Evidence Register is where an engineering team works.

Reading a row

ReadTo answer
Control title and severityWhat is being asserted, and how seriously the scanner rates it
Failing and evaluated resource countsHow much of the estate this covers, not just that it failed
Failing resource identifiers, and regionsExactly what to open
Governance implicationWhy this matters, in terms you can take to a stakeholder
First actionWhere to start
Closure evidenceWhat would demonstrate it is done

Start with reach, not order

The register is ranked, but ranking is not a work order. A contained finding on a production resource may matter more to you than a broad one across development accounts, and the assessment cannot know which is which.

Use the failing resource count and regions to decide.

The denominator matters

A control failing on 3 of 4 resources is a different situation from one failing on 3 of 300. Both appear as failed controls; only the evaluated count distinguishes them.

When the identifier list is truncated

A bounded number of resource identifiers is tracked per control. The register states explicitly whether the list is complete, so a short list is never mistaken for the whole set.

Closing a finding

Closure evidence describes what would show the control now passes. The honest test is the next assessment: a control that failed before, was evaluated again, and now passes is reported as closed. One that was not evaluated at all is reported as not re-assessed, which is not the same thing. See What changed since the last assessment.

How to obtain it

Produced with every successful assessment, and available on request. See The Evidence Register.