Evidence & Findings
From control to governance statement
A version-controlled mapping states what each failed control means in governance terms, resolved on the control and never on the AWS service.
A failed control identifier means nothing to a board. The mapping is what turns it into a governance statement.
Keyed on the control, never the service
The mapping resolves on the control, in this order:
| Order | Key | Used when |
|---|---|---|
| 1 | The exact control identifier | The consequence is specific enough that a family sentence would understate it |
| 2 | An assertion family | The pattern keys on what the check asserts, such as public access, encryption, multi-factor authentication or backup |
| 3 | A capability family | The rare case where the AWS service is the governance capability, such as whether threat detection is enabled at all |
| 4 | Unclassified | Nothing matched. No interpretation is offered |
The third is consulted last and is separated so it can be reviewed as the exception it is.
What a mapped control carries
| Field | Purpose |
|---|---|
| Governance issue | What the failure means, in one line a director can act on |
| Why it matters | The consequence, stated without exaggeration |
| First action | What management should do first |
| Control class | Preventive or detective. Materiality treats them differently |
| Reachability | Whether the concern is reachable from outside |
| Owner role | Who typically owns it |
The concerns covered
Privileged access, credential lifecycle, network exposure, data protection at rest and in transit, key and secret custody, embedded secrets, audit logging, threat detection coverage, configuration recording, supported and patched versions, recovery and redundancy configuration, and operational visibility.
What no entry may assert
No entry may assert a regulatory obligation, a framework requirement, a financial loss, a likelihood, or a materiality band. None of those are in the evidence.
Versioned
The mapping carries a version, and each pack can be traced to the wording that produced it.
