Verification
Why this section exists
A governance assessment nobody can check is an opinion. This section is how to check GovIntel rather than take its word for anything.
GovIntel asks you to create a role in your production AWS account, and then asks your board to rely on what it reports. Both are trust requests, and both should be verifiable.
What you can check yourself
| Claim | How |
|---|---|
| The access is read-only and denies data-plane reads | Read the role in your own IAM console |
| Only one workflow can assume it | Read the trust policy conditions |
| Access expires on the date you set | Read the same conditions, and the deny statement |
| GovIntel did only what it says | Filter your CloudTrail on the session name |
| The score follows the published method | Recompute it from the pack's own methodology page |
| A finding is real | Open the resource the register names |
| Movement since last time is real | Read the comparison states and their gating |
None of those require GovIntel's cooperation. All of them use information you already hold.
What you cannot check, and should know
The correctness of an individual control result against the account it describes has not been independently audited. That is stated plainly rather than left to be discovered. See What GovIntel validates about itself.
Who this section is for
Security reviewers, auditors, technical evaluators and anyone conducting diligence. It assumes technical literacy but no knowledge of GovIntel.
Where to start
Verify the access boundary is the one that matters most, because it is the claim with the most consequence if it were false.
