- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
",t};e.buildCustomizationMenuUi=t;function n(e){let t='
",t}function s(e){let n=e.filter.currentValue||e.filter.defaultValue,t='${e.filter.label}
`,e.filter.options.forEach(s=>{let o=s.id===n;t+=``}),t+="${e.filter.label}
`,t+=`account_id
Type: STRING
arn
Type: STRING
Provider name: arn
Description: The Amazon Resource Name (ARN) of the framework.
compliance_type
Type: STRING
Provider name: complianceType
Description: The compliance type that the framework supports, such as CIS or HIPAA.
control_sets
Type: UNORDERED_LIST_STRUCT
Provider name: controlSets
Description: The control sets that are associated with the framework.
controls
UNORDERED_LIST_STRUCT
controls
action_plan_instructions
STRING
actionPlanInstructions
action_plan_title
STRING
actionPlanTitle
arn
STRING
arn
control_mapping_sources
UNORDERED_LIST_STRUCT
controlMappingSources
source_description
STRING
sourceDescription
source_frequency
STRING
sourceFrequency
source_id
STRING
sourceId
source_keyword
STRUCT
sourceKeyword
keyword_input_type
STRING
keywordInputType
SELECT_FROM_LIST
is used when mapping a data source for automated evidence.keywordInputType
is SELECT_FROM_LIST
, a keyword must be selected to collect automated evidence. For example, this keyword can be a CloudTrail event name, a rule name for Config, a Security Hub control, or the name of an Amazon Web Services API call.UPLOAD_FILE
and INPUT_TEXT
are only used when mapping a data source for manual evidence.keywordInputType
is UPLOAD_FILE
, a file must be uploaded as manual evidence.keywordInputType
is INPUT_TEXT
, text must be entered as manual evidence.keyword_value
STRING
keywordValue
keywordValue
that you specify depends on the type of rule:keywordValue
. You can find the rule identifier from the list of Config managed rules. For some rules, the rule identifier is different from the rule name. For example, the rule name restricted-ssh
has the following rule identifier: INCOMING_SSH_DISABLED
. Make sure to use the rule identifier, not the rule name. Keyword example for managed rules:keywordValue
: S3_BUCKET_ACL_PROHIBITED
keywordValue
by adding the Custom_
prefix to the rule name. This prefix distinguishes the custom rule from a managed rule. Keyword example for custom rules:keywordValue
: Custom_my-custom-config-rule
keywordValue
by adding the Custom_
prefix to the rule name. In addition, you remove the suffix ID that appears at the end of the rule name. Keyword examples for service-linked rules:keywordValue
: Custom_CustomRuleForAccount-conformance-pack
keywordValue
: Custom_OrgConfigRule-s3-bucket-versioning-enabled
keywordValue
is case sensitive. If you enter a value incorrectly, Audit Manager might not recognize the data source mapping. As a result, you might not successfully collect evidence from that data source as intended. Keep in mind the following requirements, depending on the data source type that you’re using.keywordValue
is the rule identifier in ALL_CAPS_WITH_UNDERSCORES
. For example, CLOUDWATCH_LOG_GROUP_ENCRYPTED
. For accuracy, we recommend that you reference the list of supported Config managed rules.keywordValue
has the Custom_
prefix followed by the custom rule name. The format of the custom rule name itself may vary. For accuracy, we recommend that you visit the Config console to verify your custom rule name.keywordValue
is written as serviceprefix_ActionName
. For example, iam_ListGroups
. For accuracy, we recommend that you reference the list of supported API calls.keywordValue
is written as serviceprefix_ActionName
. For example, cloudtrail_StartLogging
. For accuracy, we recommend that you review the Amazon Web Services service prefix and action names in the Service Authorization Reference.source_name
STRING
sourceName
source_set_up_option
STRING
sourceSetUpOption
sourceSetUpOption
, Audit Manager automatically infers and populates the correct value based on the sourceType
that you specify.source_type
STRING
sourceType
AWS_Cloudtrail
, AWS_Config
, AWS_Security_Hub
, AWS_API_Call
, or MANUAL
.Core_Control
or a Common_Control
.troubleshooting_text
STRING
troubleshootingText
control_sources
STRING
controlSources
created_at
TIMESTAMP
createdAt
created_by
STRING
createdBy
description
STRING
description
id
STRING
id
last_updated_at
TIMESTAMP
lastUpdatedAt
last_updated_by
STRING
lastUpdatedBy
name
STRING
name
state
STRING
state
END_OF_SUPPORT
state is applicable to standard controls only. This state indicates that the standard control can still be used to collect evidence, but Audit Manager is no longer updating or maintaining that control.testing_information
STRING
testingInformation
type
STRING
type
id
STRING
id
name
STRING
name
control_sources
Type: STRING
Provider name: controlSources
Description: The control data sources where Audit Manager collects evidence from.
created_at
Type: TIMESTAMP
Provider name: createdAt
Description: The time when the framework was created.
created_by
Type: STRING
Provider name: createdBy
Description: The user or role that created the framework.
description
Type: STRING
Provider name: description
Description: The description of the framework.
id
Type: STRING
Provider name: id
Description: The unique identifier for the framework.
last_updated_at
Type: TIMESTAMP
Provider name: lastUpdatedAt
Description: The time when the framework was most recently updated.
last_updated_by
Type: STRING
Provider name: lastUpdatedBy
Description: The user or role that most recently updated the framework.
logo
Type: STRING
Provider name: logo
Description: The logo that’s associated with the framework.
name
Type: STRING
Provider name: name
Description: The name of the framework.
tags
Type: UNORDERED_LIST_STRING
type
Type: STRING
Provider name: type
Description: Specifies whether the framework is a standard framework or a custom framework.