Guidance
If you have accounts listed in AWS security groups shown in your reports that do not have MFA enabled, explain why in the Evidence Description.
If, due to a business need, you do not restrict access to the security groups listed in your reports, explain why in the Evidence Description.
If you do not use AWS as your CSP for in-scope production systems, note this in the Evidence Description.
Related Articles
Example Evidence

