When running some CCS checks with positive evidence enabled, you notice that when the check passes correctly there is no evidence reported by CCS on why it passed.
CCS 12.6.x
CCS 12.7
CCS 12.8
This is working by design. Positive evidence will not be reported by a complex check.
To be able to collect the required data for some CIS Benchmark checks, some checks need to be created with complex steps to be able to verify if the check passes or fails.
Below is an example of a 'complex check' in CCS.
(Note the symbol of the check which denotes it as being a complex check, and also information that complex checks cannot be shown or modified)
See the Additional Information section below on support from Broadcom for CCS standards and checks.