Findings
Governance implication
What a failed control means in governance terms, taken from a version-controlled mapping keyed on the control and never on the AWS service.
What it is
One sentence stating what a failed control means, drawn from the governance mapping.
Why it is keyed on the control
Because keying it on the AWS service was wrong. One sentence per service applied to every control that service could fail, so a database reachable from the internet was reported as a backup and redundancy concern.
The eleven database controls in the scanner's catalogue span six distinct governance concerns. No per-service sentence can be correct for more than one of them.
How it resolves
Exact control identifier first, then an assertion family keyed on what the check asserts, then the short list of capability families where the AWS service genuinely is the governance capability, then unclassified.
What it may never assert
No entry may claim a regulatory obligation, a framework requirement, a financial loss, a likelihood, or a materiality band. None of those are in the evidence.
What it does not mean
It is GovIntel's interpretation, versioned and traceable. It is not the scanner's remediation text, which is deliberately excluded from what a customer receives.
