Evidence & Findings

From finding to control

How a raw scanner record becomes a scored control: status classification, identifier extraction, then collapse to distinct controls.

Currentengine 9.0.0Verified 2026-08-30

The four steps

  1. Admission. Only files recognised as control evidence are read. Anything else is listed in the assessment note and ignored.
  2. Status. Each record is classified as passing, failing, or unclassifiable. Anything that cannot be classified is excluded from both sides of the pass rate and counted separately.
  3. Identity. Each record yields the identifier of the control it evaluated, and the identifiers of the resources it evaluated it against.
  4. Collapse. Records are grouped by control identifier. A control failing on forty resources becomes one failed control carrying forty resources.

What survives the collapse

Everything a reader needs:

RetainedUsed for
The control identifier and titleNaming the finding
SeverityWeighting the score, and ordering the register
The failing resource identifiersActing on it, and computing reach
The regions those resources are inComputing reach
The count evaluated, not only the count failedStating the denominator

Why the resource identifiers are kept

They are what materiality is computed from. Deduplication sets the count aside for scoring; it does not discard it.

A bounded number of resource identifiers is tracked per control. Where the list was truncated, the pack says so rather than presenting a short list as complete.

Resource identity

A resource identifier is parsed to establish which region and which service it belongs to, and whether the control governs the account as a whole rather than any particular resource. Account-scoped controls reach everything, whatever their resource count.