AWS Evidence
Security Hub posture
Whether the account's own security findings service is enabled, aggregated and administered, read as context and applied as a scoring penalty.
What it is
Four observations: whether Security Hub is enabled, whether a delegated administrator is configured, whether cross-region finding aggregation is on, and how many active failed findings exist.
Why it matters
These describe whether the account has a working view of its own security posture. An account with the service disabled is not necessarily less secure, but it is less observed, and that is a governance position.
How GovIntel applies it
As penalties against the security domain score: 12 for the service being disabled, 6 for aggregation being off, 4 for no delegated administrator.
The active finding count is counted through a paginated query with an explicit filter, and is null when it cannot be retrieved rather than silently reported as zero.
What it does not mean
It is context, not a scored domain of its own, and it does not count towards evidence confidence. The finding count is not used in scoring.
