Evidence & Findings

From control to governance statement

A version-controlled mapping states what each failed control means in governance terms, resolved on the control and never on the AWS service.

Currentengine 9.0.0Verified 2026-08-30

A failed control identifier means nothing to a board. The mapping is what turns it into a governance statement.

Keyed on the control, never the service

The mapping resolves on the control, in this order:

OrderKeyUsed when
1The exact control identifierThe consequence is specific enough that a family sentence would understate it
2An assertion familyThe pattern keys on what the check asserts, such as public access, encryption, multi-factor authentication or backup
3A capability familyThe rare case where the AWS service is the governance capability, such as whether threat detection is enabled at all
4UnclassifiedNothing matched. No interpretation is offered

The third is consulted last and is separated so it can be reviewed as the exception it is.

What a mapped control carries

FieldPurpose
Governance issueWhat the failure means, in one line a director can act on
Why it mattersThe consequence, stated without exaggeration
First actionWhat management should do first
Control classPreventive or detective. Materiality treats them differently
ReachabilityWhether the concern is reachable from outside
Owner roleWho typically owns it

The concerns covered

Privileged access, credential lifecycle, network exposure, data protection at rest and in transit, key and secret custody, embedded secrets, audit logging, threat detection coverage, configuration recording, supported and patched versions, recovery and redundancy configuration, and operational visibility.

What no entry may assert

No entry may assert a regulatory obligation, a framework requirement, a financial loss, a likelihood, or a materiality band. None of those are in the evidence.

Versioned

The mapping carries a version, and each pack can be traced to the wording that produced it.