aws-iam-policy-types
Version:
Autogenerated Typescript types for AWS IAM Policy and enums for all policy actions
601 lines (600 loc) • 26.2 kB
TypeScript
/**
* All IAM policy actions for AWS Security Hub (SECURITYHUB)
*
* Extracted by `aws-iam-policy` from
* https://docs.aws.amazon.com/service-authorization/latest/reference/list_awssecurityhub.html
*
* 2025-02-24T21:49:39.402Z
*/
export declare enum AwsSecurityhubActions {
/**
* Grants permission to accept Security Hub invitations to become a member account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_AcceptAdministratorInvitation.html
*/
AcceptAdministratorInvitation = "securityhub:AcceptAdministratorInvitation",
/**
* Grants permission to accept Security Hub invitations to become a member account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_AcceptInvitation.html
*/
AcceptInvitation = "securityhub:AcceptInvitation",
/**
* Grants permission to delete one or more automation rules in Security Hub
*
* See https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules
*/
BatchDeleteAutomationRules = "securityhub:BatchDeleteAutomationRules",
/**
* Grants permission to disable standards in Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchDisableStandards.html
*/
BatchDisableStandards = "securityhub:BatchDisableStandards",
/**
* Grants permission to enable standards in Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchEnableStandards.html
*/
BatchEnableStandards = "securityhub:BatchEnableStandards",
/**
* Grants permission to retrieve a list of details for automation rules from Secur
* ity Hub based on rule Amazon Resource Names (ARNs)
*
* See https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules
*/
BatchGetAutomationRules = "securityhub:BatchGetAutomationRules",
/**
* Grants permission to retrieve information about configuration policies associat
* ed with a specific list of member accounts and organizational units of the call
* ing account's organization
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchGetConfigurationPolicyAssociations.html
*/
BatchGetConfigurationPolicyAssociations = "securityhub:BatchGetConfigurationPolicyAssociations",
/**
* Grants permission to get the enablement and compliance status of controls, the
* findings count for controls, and the overall security score for controls on the
* Security Hub console
*
* See https://docs.aws.amazon.com/securityhub/latest/userguide/iam-permissions-controls-standards.html
*/
BatchGetControlEvaluations = "securityhub:BatchGetControlEvaluations",
/**
* Grants permission to get details about specific security controls identified by
* ID or ARN
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchGetSecurityControls.html
*/
BatchGetSecurityControls = "securityhub:BatchGetSecurityControls",
/**
* Grants permission to get the enablement status of a batch of security controls
* in standards
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchGetStandardsControlAssociations.html
*/
BatchGetStandardsControlAssociations = "securityhub:BatchGetStandardsControlAssociations",
/**
* Grants permission to import findings into Security Hub from an integrated produ
* ct
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchImportFindings.html
*/
BatchImportFindings = "securityhub:BatchImportFindings",
/**
* Grants permission to update one or more automation rules from Security Hub base
* d on rule Amazon Resource Names (ARNs) and input parameters
*
* See https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules
*/
BatchUpdateAutomationRules = "securityhub:BatchUpdateAutomationRules",
/**
* Grants permission to update customer-controlled fields for a selected set of Se
* curity Hub findings
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchUpdateFindings.html
*/
BatchUpdateFindings = "securityhub:BatchUpdateFindings",
/**
* Grants permission to update the enablement status of a batch of security contro
* ls in standards
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchUpdateStandardsControlAssociations.html
*/
BatchUpdateStandardsControlAssociations = "securityhub:BatchUpdateStandardsControlAssociations",
/**
* Grants permission to create custom actions in Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateActionTarget.html
*/
CreateActionTarget = "securityhub:CreateActionTarget",
/**
* Grants permission to create an automation rule based on input parameters
*
* See https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules
*/
CreateAutomationRule = "securityhub:CreateAutomationRule",
/**
* Grants permission to create a configuration policy to manage organization membe
* r settings in Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateConfigurationPolicy.html
*/
CreateConfigurationPolicy = "securityhub:CreateConfigurationPolicy",
/**
* Grants permission to create a finding aggregator, which contains the cross-Regi
* on finding aggregation configuration
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateFindingAggregator.html
*/
CreateFindingAggregator = "securityhub:CreateFindingAggregator",
/**
* Grants permission to create insights in Security Hub. Insights are collections
* of related findings
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateInsight.html
*/
CreateInsight = "securityhub:CreateInsight",
/**
* Grants permission to create member accounts in Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateMembers.html
*/
CreateMembers = "securityhub:CreateMembers",
/**
* Grants permission to decline Security Hub invitations to become a member accoun
* t
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeclineInvitations.html
*/
DeclineInvitations = "securityhub:DeclineInvitations",
/**
* Grants permission to delete custom actions in Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteActionTarget.html
*/
DeleteActionTarget = "securityhub:DeleteActionTarget",
/**
* Grants permission to delete an existing configuration policy
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteConfigurationPolicy.html
*/
DeleteConfigurationPolicy = "securityhub:DeleteConfigurationPolicy",
/**
* Grants permission to delete a finding aggregator, which disables finding aggreg
* ation across Regions
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteFindingAggregator.html
*/
DeleteFindingAggregator = "securityhub:DeleteFindingAggregator",
/**
* Grants permission to delete insights from Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteInsight.html
*/
DeleteInsight = "securityhub:DeleteInsight",
/**
* Grants permission to delete Security Hub invitations to become a member account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteInvitations.html
*/
DeleteInvitations = "securityhub:DeleteInvitations",
/**
* Grants permission to delete Security Hub member accounts
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteMembers.html
*/
DeleteMembers = "securityhub:DeleteMembers",
/**
* Grants permission to retrieve a list of custom actions using the API
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeActionTargets.html
*/
DescribeActionTargets = "securityhub:DescribeActionTargets",
/**
* Grants permission to retrieve information about the hub resource in your accoun
* t
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeHub.html
*/
DescribeHub = "securityhub:DescribeHub",
/**
* Grants permission to describe the organization configuration for Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeOrganizationConfiguration.html
*/
DescribeOrganizationConfiguration = "securityhub:DescribeOrganizationConfiguration",
/**
* Grants permission to retrieve information about the available Security Hub prod
* uct integrations
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeProducts.html
*/
DescribeProducts = "securityhub:DescribeProducts",
/**
* Grants permission to retrieve information about Security Hub standards
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeStandards.html
*/
DescribeStandards = "securityhub:DescribeStandards",
/**
* Grants permission to retrieve information about Security Hub standards controls
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeStandardsControls.html
*/
DescribeStandardsControls = "securityhub:DescribeStandardsControls",
/**
* Grants permission to disable the findings importing for a Security Hub integrat
* ed product
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisableImportFindingsForProduct.html
*/
DisableImportFindingsForProduct = "securityhub:DisableImportFindingsForProduct",
/**
* Grants permission to remove the Security Hub administrator account for your org
* anization
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisableOrganizationAdminAccount.html
*/
DisableOrganizationAdminAccount = "securityhub:DisableOrganizationAdminAccount",
/**
* Grants permission to disable Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisableSecurityHub.html
*/
DisableSecurityHub = "securityhub:DisableSecurityHub",
/**
* Grants permission to a Security Hub member account to disassociate from the ass
* ociated administrator account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisassociateFromAdministratorAccount.html
*/
DisassociateFromAdministratorAccount = "securityhub:DisassociateFromAdministratorAccount",
/**
* Grants permission to a Security Hub member account to disassociate from the ass
* ociated master account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisassociateFromMasterAccount.html
*/
DisassociateFromMasterAccount = "securityhub:DisassociateFromMasterAccount",
/**
* Grants permission to disassociate Security Hub member accounts from the associa
* ted administrator account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisassociateMembers.html
*/
DisassociateMembers = "securityhub:DisassociateMembers",
/**
* Grants permission to enable the findings importing for a Security Hub integrate
* d product
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_EnableImportFindingsForProduct.html
*/
EnableImportFindingsForProduct = "securityhub:EnableImportFindingsForProduct",
/**
* Grants permission to designate a Security Hub administrator account for your or
* ganization
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_EnableOrganizationAdminAccount.html
*/
EnableOrganizationAdminAccount = "securityhub:EnableOrganizationAdminAccount",
/**
* Grants permission to enable Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_EnableSecurityHub.html
*/
EnableSecurityHub = "securityhub:EnableSecurityHub",
/**
* Grants permission to retrieve insight results by providing a set of filters ins
* tead of an insight ARN
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetAdhocInsightResults.html
*/
GetAdhocInsightResults = "securityhub:GetAdhocInsightResults",
/**
* Grants permission to retrieve details about the Security Hub administrator acco
* unt
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetAdministratorAccount.html
*/
GetAdministratorAccount = "securityhub:GetAdministratorAccount",
/**
* Grants permission to get a complete overview of one configuration policy create
* d by the calling account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetConfigurationPolicy.html
*/
GetConfigurationPolicy = "securityhub:GetConfigurationPolicy",
/**
* Grants permission to retrieve information about a configuration policy associat
* ed with a member account or organizational unit of the calling account's organi
* zation
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetConfigurationPolicyAssociation.html
*/
GetConfigurationPolicyAssociation = "securityhub:GetConfigurationPolicyAssociation",
/**
* Grants permission to retrieve a security score and counts of finding and contro
* l statuses for a security standard
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetControlFindingSummary.html
*/
GetControlFindingSummary = "securityhub:GetControlFindingSummary",
/**
* Grants permission to retrieve a list of the standards that are enabled in Secur
* ity Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetEnabledStandards.html
*/
GetEnabledStandards = "securityhub:GetEnabledStandards",
/**
* Grants permission to retrieve details for a finding aggregator, which configure
* s finding aggregation across Regions
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFindingAggregator.html
*/
GetFindingAggregator = "securityhub:GetFindingAggregator",
/**
* Grants permission to retrieve a list of finding history from Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFindingHistory.html
*/
GetFindingHistory = "securityhub:GetFindingHistory",
/**
* Grants permission to retrieve a list of findings from Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFindings.html
*/
GetFindings = "securityhub:GetFindings",
/**
* Grants permission to retrieve the end date for an account's free trial of Secur
* ity Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFreeTrialEndDate.html
*/
GetFreeTrialEndDate = "securityhub:GetFreeTrialEndDate",
/**
* Grants permission to retrieve information about Security Hub usage during the f
* ree trial period
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFreeTrialUsage.html
*/
GetFreeTrialUsage = "securityhub:GetFreeTrialUsage",
/**
* Grants permission to retrieve an insight finding trend from Security Hub in ord
* er to generate a graph
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetInsightFindingTrend.html
*/
GetInsightFindingTrend = "securityhub:GetInsightFindingTrend",
/**
* Grants permission to retrieve insight results from Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetInsightResults.html
*/
GetInsightResults = "securityhub:GetInsightResults",
/**
* Grants permission to retrieve Security Hub insights
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetInsights.html
*/
GetInsights = "securityhub:GetInsights",
/**
* Grants permission to retrieve the count of Security Hub membership invitations
* sent to the account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetInvitationsCount.html
*/
GetInvitationsCount = "securityhub:GetInvitationsCount",
/**
* Grants permission to retrieve details about the Security Hub master account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetMasterAccount.html
*/
GetMasterAccount = "securityhub:GetMasterAccount",
/**
* Grants permission to retrieve the details of Security Hub member accounts
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetMembers.html
*/
GetMembers = "securityhub:GetMembers",
/**
* Grants permission to get the definition details of a specific security control
* identified by ID
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetSecurityControlDefinition.html
*/
GetSecurityControlDefinition = "securityhub:GetSecurityControlDefinition",
/**
* Grants permission to retrieve information about Security Hub usage by accounts
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetUsage.html
*/
GetUsage = "securityhub:GetUsage",
/**
* Grants permission to invite other AWS accounts to become Security Hub member ac
* counts
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_InviteMembers.html
*/
InviteMembers = "securityhub:InviteMembers",
/**
* Grants permission to retrieve a list of automation rules and their metadata for
* the calling account from Security Hub
*
* See https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules
*/
ListAutomationRules = "securityhub:ListAutomationRules",
/**
* Grants permission to list the summaries of all configuration policies created b
* y the calling account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListConfigurationPolicies.html
*/
ListConfigurationPolicies = "securityhub:ListConfigurationPolicies",
/**
* Grants permission to retrieve information about all configuration policies asso
* ciationed with all member accounts and organizational units of the calling acco
* unt's organization
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListConfigurationPolicyAssociations.html
*/
ListConfigurationPolicyAssociations = "securityhub:ListConfigurationPolicyAssociations",
/**
* Grants permission to retrieve a list of controls for a standard, including the
* control IDs, statuses and finding counts
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListControlEvaluationSummaries.html
*/
ListControlEvaluationSummaries = "securityhub:ListControlEvaluationSummaries",
/**
* Grants permission to retrieve the Security Hub integrated products that are cur
* rently enabled
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListEnabledProductsForImport.html
*/
ListEnabledProductsForImport = "securityhub:ListEnabledProductsForImport",
/**
* Grants permission to retrieve a list of finding aggregators, which contain the
* cross-Region finding aggregation configuration
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateFindingAggregator.html
*/
ListFindingAggregators = "securityhub:ListFindingAggregators",
/**
* Grants permission to retrieve the Security Hub invitations sent to the account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListInvitations.html
*/
ListInvitations = "securityhub:ListInvitations",
/**
* Grants permission to retrieve details about Security Hub member accounts associ
* ated with the administrator account
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListMembers.html
*/
ListMembers = "securityhub:ListMembers",
/**
* Grants permission to list the Security Hub administrator accounts for your orga
* nization
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListOrganizationAdminAccounts.html
*/
ListOrganizationAdminAccounts = "securityhub:ListOrganizationAdminAccounts",
/**
* Grants permission to retrieve a list of security control definitions, which con
* tain details for security controls in the current region
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListSecurityControlDefinitions.html
*/
ListSecurityControlDefinitions = "securityhub:ListSecurityControlDefinitions",
/**
* Grants permission to list the enablement status of a security control in standa
* rds
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListStandardsControlAssociations.html
*/
ListStandardsControlAssociations = "securityhub:ListStandardsControlAssociations",
/**
* Grants permission to list of tags associated with a resource
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListTagsForResource.html
*/
ListTagsForResource = "securityhub:ListTagsForResource",
/**
* Grants permission to use a custom action to send Security Hub findings to Amazo
* n EventBridge
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_SendFindingEvents.html
*/
SendFindingEvents = "securityhub:SendFindingEvents",
/**
* Grants permission to use a custom action to send Security Hub insights to Amazo
* n EventBridge
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_SendInsightEvents.html
*/
SendInsightEvents = "securityhub:SendInsightEvents",
/**
* Grants permission to associate a configuration policy with a member account or
* organizational unit in the calling account's organization
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_StartConfigurationPolicyAssociation.html
*/
StartConfigurationPolicyAssociation = "securityhub:StartConfigurationPolicyAssociation",
/**
* Grants permission to remove a configuration policy association from a member ac
* count or organizational unit in the calling account's organization
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_StartConfigurationPolicyDisassociation.html
*/
StartConfigurationPolicyDisassociation = "securityhub:StartConfigurationPolicyDisassociation",
/**
* Grants permission to add tags to a Security Hub resource
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_TagResource.html
*/
TagResource = "securityhub:TagResource",
/**
* Grants permission to remove tags from a Security Hub resource
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UntagResource.html
*/
UntagResource = "securityhub:UntagResource",
/**
* Grants permission to update custom actions in Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateActionTarget.html
*/
UpdateActionTarget = "securityhub:UpdateActionTarget",
/**
* Grants permission to update an existing configuration policy
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateConfigurationPolicy.html
*/
UpdateConfigurationPolicy = "securityhub:UpdateConfigurationPolicy",
/**
* Grants permission to update a finding aggregator, which contains the cross-Regi
* on finding aggregation configuration
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateFindingAggregator.html
*/
UpdateFindingAggregator = "securityhub:UpdateFindingAggregator",
/**
* Grants permission to update Security Hub findings
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateFindings.html
*/
UpdateFindings = "securityhub:UpdateFindings",
/**
* Grants permission to update insights in Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateInsight.html
*/
UpdateInsight = "securityhub:UpdateInsight",
/**
* Grants permission to update the organization configuration for Security Hub
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateOrganizationConfiguration.html
*/
UpdateOrganizationConfiguration = "securityhub:UpdateOrganizationConfiguration",
/**
* Grants permission to update properties of a specific security control identifie
* d by ID or ARN
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateSecurityControl.html
*/
UpdateSecurityControl = "securityhub:UpdateSecurityControl",
/**
* Grants permission to update Security Hub configuration
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateSecurityHubConfiguration.html
*/
UpdateSecurityHubConfiguration = "securityhub:UpdateSecurityHubConfiguration",
/**
* Grants permission to update Security Hub standards controls
*
* See https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateStandardsControl.html
*/
UpdateStandardsControl = "securityhub:UpdateStandardsControl"
}