Security Hub Configuration Policy

Security Hub Configuration Policy in AWS defines the settings and controls applied to an account or organization within AWS Security Hub. It allows centralized management of security standards, control enablement, and configuration across multiple accounts. This resource helps ensure consistent security posture, compliance enforcement, and streamlined governance by applying policies at scale.

aws.securityhub_configuration_policy

Fields

TitleIDTypeData TypeDescription
_keycorestring
account_idcorestring
arncorestringThe ARN of the configuration policy.
configuration_policycorejsonAn object that defines how Security Hub is configured. It includes whether Security Hub is enabled or disabled, a list of enabled security standards, a list of enabled or disabled security controls, and a list of custom parameter values for specified controls. If the policy includes a list of security controls that are enabled, Security Hub disables all other controls (including newly released controls). If the policy includes a list of security controls that are disabled, Security Hub enables all other controls (including newly released controls).
created_atcoretimestampThe date and time, in UTC and ISO 8601 format, that the configuration policy was created.
descriptioncorestringThe description of the configuration policy.
idcorestringThe UUID of the configuration policy.
namecorestringThe name of the configuration policy.
tagscorehstore
updated_atcoretimestampThe date and time, in UTC and ISO 8601 format, that the configuration policy was last updated.