AWS Evidence

Security Hub posture

Whether the account's own security findings service is enabled, aggregated and administered, read as context and applied as a scoring penalty.

Currentengine 9.0.0Verified 2026-08-30

What it is

Four observations: whether Security Hub is enabled, whether a delegated administrator is configured, whether cross-region finding aggregation is on, and how many active failed findings exist.

Why it matters

These describe whether the account has a working view of its own security posture. An account with the service disabled is not necessarily less secure, but it is less observed, and that is a governance position.

How GovIntel applies it

As penalties against the security domain score: 12 for the service being disabled, 6 for aggregation being off, 4 for no delegated administrator.

The active finding count is counted through a paginated query with an explicit filter, and is null when it cannot be retrieved rather than silently reported as zero.

What it does not mean

It is context, not a scored domain of its own, and it does not count towards evidence confidence. The finding count is not used in scoring.