Verification
Trace a finding to a resource
Walk a register row back to the actual resource in your account and confirm the control result describes what is really configured there.
This is the check that establishes whether the assessment is right about your environment, rather than merely internally consistent.
The Evidence Register is produced with every successful assessment and is available on request. Ask for it before starting this check.
The walk
- Take a row from the Evidence Register.
- Note the control identifier and what it asserts.
- Take the failing resource identifiers and their regions.
- Open one of those resources in your own console.
- Confirm the configuration the control asserts is genuinely absent.
Repeat for the top findings by severity and by reach.
What to confirm
| Claim in the row | Confirm |
|---|---|
| This control failed | The configuration really is as reported |
| On these resources | Each identifier resolves to a real resource you own |
| In these regions | The regions match |
| Failing count against evaluated count | The denominator is plausible for your estate |
Where a mismatch would matter
A resource identifier that does not resolve, a control reported failing on a resource that is correctly configured, or an evaluated count far below the number of such resources you actually run. Any of those is worth raising.
The list may be truncated
A bounded number of resource identifiers is tracked per control, and the register states explicitly whether the list is complete. A truncated list is not evidence that only those resources failed.
The honest limit
GovIntel has validated that the pipeline produces a defensible number from real evidence. Nobody has audited the individual control results against the account they describe. That check needs a person who knows the environment, which is you.
If you do it, the result is worth telling us either way.
