AWS Evidence
Evidence capture state
One of eight states describing what happened to a collector, distinguishing a crash from a healthy empty account and a gap from a pass.
The states
| State | Meaning |
|---|---|
| Assessed, healthy | Collected, scored, in good shape |
| Assessed, issues found | Collected, scored, something is failing |
| Collected, not rated | Evidence arrived but was too thin to rate |
| No applicable resources | Nothing of this kind exists. Not a fault |
| Collector failed | It ran and errored. GovIntel's to fix |
| Permission denied | A required permission was missing |
| Unavailable | Did not run, or was skipped |
| Captured | A context collector with no governance position |
Why eight and not two
There used to be two: captured, and unavailable. Those could not distinguish a collector that crashed from one never configured, nor an account with four hundred healthy resources from one with a single resource.
Both conflations mislead in the customer's favour, which is the direction that costs trust.
Ordered most specific first
A collector that failed is reported as failed even though its absence also means the domain went unscored. One is GovIntel's to fix; the other may simply be an account with nothing of that kind in it.
What it does not mean
A collector reported as captured has not established a governance position. Account metadata and Security Hub status are context and never count towards evidence confidence.
