AWS Evidence

Control checks

The scanner's control results across every enabled region, collected at three severities, with both passing and failing outcomes required.

Currentengine 9.0.0Verified 2026-08-30

What it is

The output of an external scanner, run across every enabled region, at critical, high and medium severity.

Why both outcomes are collected

The security domain is scored as a pass rate. Without passing results there is no denominator, and the domain would be reported as not assessed rather than scored.

How GovIntel applies it

Records are collapsed to distinct controls before scoring. Records that cannot be classified are excluded from both sides and counted separately. Only files recognised as control evidence are read.

The scanner exits with a distinct status when any check fails, which is the normal outcome for every real account. That status is handled explicitly, so a completed scan of an imperfect account is never recorded as a failed collector.

What it does not mean

The scanner's catalogue is the ceiling on security coverage. A control it does not implement is a control the assessment cannot report.