Skip to main content

security_controls_list_only

Lists security_controls in a region or regions, for all properties use security_controls

Overview

Namesecurity_controls_list_only
TypeResource
DescriptionA security control in Security Hub describes a security best practice related to a specific resource.
Idaws.securityhub.security_controls_list_only

Fields

NameDatatypeDescription
security_control_idstringThe unique identifier of a security control across standards. Values for this field typically consist of an AWS service name and a number, such as APIGateway.3.
security_control_arnstringThe Amazon Resource Name (ARN) for a security control across standards, such as `arn:aws:securityhub:eu-central-1:123456789012:security-control/S3.1`. This parameter doesn't mention a specific standard.
last_update_reasonstringThe most recent reason for updating the customizable properties of a security control. This differs from the UpdateReason field of the BatchUpdateStandardsControlAssociations API, which tracks the reason for updating the enablement status of a control. This field accepts alphanumeric characters in addition to white spaces, dashes, and underscores.
parametersobjectAn object that identifies the name of a control parameter, its current value, and whether it has been customized.
regionstringAWS region.

Methods

NameAccessible byRequired Params
list_resourcesSELECTregion

SELECT examples

Lists all security_controls in a region.

SELECT
region,
security_control_id
FROM aws.securityhub.security_controls_list_only
WHERE region = 'us-east-1';

Permissions

For permissions required to operate on the security_controls_list_only resource, see security_controls