Evidence & Findings
The Evidence Register
A derived, customer-safe file listing every failed control with the resources it was observed on. Produced with every assessment, available on request.
The board pack is written for a board. The Evidence Register is the same assessment in a form an engineering team can work through.
The columns
| Column | Content |
|---|---|
| Rank | Position in the register |
| Control identifier | The scanner's own identifier |
| Control title | What the check asserts |
| Severity | Critical, high or medium |
| AWS service | The service the resources belong to |
| Failing resource count | How many distinct resources failed |
| Evaluated resource count | How many were evaluated, so the denominator is visible |
| Failing resource identifiers | The full identifiers, unmasked |
| Regions | Where the failures were observed |
| Resource identifiers complete | Whether the list was truncated |
| Governance implication | What the failure means |
| First action | What to do first |
| Closure evidence | What would demonstrate it is closed |
One row per failed control, all of them, at every severity.
It is derived, not an evidence dump
Deliberately absent: the raw scanner records, the scanner's own remediation text, its product fields, compliance framework annotations, and cost telemetry. The register is not the evidence set by another name.
The evidence set itself is a separate internal artefact with a short retention, and this file must never become a way around that.
Why the identifiers are unmasked here
You own the account and cannot act on a masked identifier. The board pack masks them instead, because the pack is the document that circulates.
How to obtain it
The Evidence Register is produced with every successful assessment and is available on request. It is not currently delivered automatically alongside the pack through your portal. Ask your GovIntel contact.
