1. Changes to policy specification for standard and control information.
2. Changes to detection engine and all detection paths to emit Pass/Fail status if the policy has associated standard/control information.
3. Data model design to accommodate requirements in 1. and 2.
4. Compliance reporting will NOT be part of 4.8.
5. Compliance views will not include in any pass fail counts the policies that were not executed/skipped on workloads because of exclusion. Pass/fail status is based on the absence/presence of violations for policy that was evaluated against a deployment.