Lacework
Access helpful articles and other FAQs on Lacework
nicky-fortinet
Article Id 410320
Description This article describes how to debug 'Not assessed' resources in FortiCNAPP Compliance.
Scope FortiCNAPP, Lacework, Compliance.
Solution

Navigate to Compliance -> Compliance.

 

Select the 'Policies' tab and note on the right-hand side the resource count. Note that the resource count lists 2 'Not assessed' resources.

 

policies.jpg

 

Select the policy to enter and see the full breakdown.

Note the four tabs inside the policies page, select the 'Not assessed' tab.

 

policies2.jpg

 

Here, the information is listed on which resources were not assessed.

 

Select the blue clipboard icon under the 'Status' column.

 

policies3.jpg

 
This will open up the information; the error listed here comes directly from the AWS Client that is invoked to perform the collection. 

 

policies4.jpg

 

The error message states that a resource control policy is denying the role access to the resource; in this instance, fixing the resource policy to allow the role access will fix the issue.