Findings

Failing resource

A specific resource a control was evaluated against and failed on. It is what makes a finding actionable and what reach is computed from.

Currentengine 9.0.0Verified 2026-08-30

What it is

An individual resource, named by its identifier, that a control failed on.

Why it is retained after deduplication

Deduplication sets resource counts aside for scoring. It does not discard them. The resources are what makes a finding actionable, and they are what materiality is computed from.

How GovIntel reports it

Full identifiers, unmasked, in the Evidence Register, which is produced with every assessment and available on request: you own the account and cannot act on a masked identifier. The board pack shortens them, because the pack is the document that circulates.

Truncation is disclosed

A bounded number of identifiers is tracked per control. Where the list was truncated, the register says so explicitly, so a short list is never mistaken for the complete set.

What it does not mean

The resource count is not a severity and not a business impact. It is one input to reach.