Overview
Who it is for
Written for boards and the executives who answer to them, and for the engineers who act on the same assessment the board reads.
The board pack is written at board altitude. It states a position, the evidence behind it, and what management should do next — without requiring the reader to know what an IAM policy is.
The reader the pack is written for
| Reader | The question they bring |
|---|---|
| Board and non-executive directors | Is this environment governed well enough to rely on, and what should we ask management? |
| CTO or CIO answering to a board | Can I show a defensible position rather than an assurance I have written myself? |
| Investor or acquirer in diligence | What does the target's cloud governance actually look like, on evidence? |
| Security or platform lead | Which controls are failing, on which resources, and in what order should we close them? |
The last row is the reason the assessment produces two artefacts rather than one. A pack a board can read is not a document an engineer can act on, and a list an engineer can act on is not a document a board can read.
What a reader needs to bring
Nothing technical. Connecting an AWS account requires someone with permission to create a CloudFormation stack in it, which is usually a platform engineer, and takes one screen. Everything after that is GovIntel's.
Who it is not for
- Anyone who needs a certification or an auditor's opinion. GovIntel issues
neither.
- Anyone assessing Azure or GCP. The assessment is AWS only.
- Anyone who needs continuous monitoring. The assessment is a point in time.
