AWS Evidence
Control checks
The scanner's control results across every enabled region, collected at three severities, with both passing and failing outcomes required.
What it is
The output of an external scanner, run across every enabled region, at critical, high and medium severity.
Why both outcomes are collected
The security domain is scored as a pass rate. Without passing results there is no denominator, and the domain would be reported as not assessed rather than scored.
How GovIntel applies it
Records are collapsed to distinct controls before scoring. Records that cannot be classified are excluded from both sides and counted separately. Only files recognised as control evidence are read.
The scanner exits with a distinct status when any check fails, which is the normal outcome for every real account. That status is handled explicitly, so a completed scan of an imperfect account is never recorded as a failed collector.
What it does not mean
The scanner's catalogue is the ceiling on security coverage. A control it does not implement is a control the assessment cannot report.
