Amazon Inspector
What this tool proves, in the authored overlay. Every recipe below names Amazon Inspector; the controls are what their output is evidence for. The mapping is this project’s opinion (overlay v3.0.0) — the upstream FedRAMP rules name no vendor and no product.
Recipes calling Amazon Inspector (2)
- partialpatch-and-vulnerability-remediationdaily
Patch Manager compliance state plus Amazon Inspector scan status and coverage — proving flaws are being found continuously (Inspector enabled and actually covering your resources) and that the fixes landed (per-node missing/failed patch counts and the time of the last scan or install)
- partialacquisition-scanning-and-sbom-inventorycontinuous
Whether the tooling that examines acquired software is switched on and covering the estate, and what it found: Inspector's per-account enablement state for each scanned resource type, the registry-wide ECR scanning configuration (scan type and frequency, and the repository filters that decide which repositories it applies to), Inspector's own coverage statistics, and a CycloneDX 1.4 or SPDX 2.3 SBOM exported per monitored resource — the component-level inventory of what was actually acquired.
Controls it carries evidence for (3)
The reverse of the join above. A mark here is the control’s own grade across the whole corpus, not its grade from this tool alone — a control this tool partly proves may be fully proved with another.
Tool names are canonical, from data/overlays/aws-services.json and data/overlays/pipeline-tools.json. The two overlays that name services spelled five of them two ways; a page keyed on the raw string would have split those in half.