- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
",t};e.buildCustomizationMenuUi=t;function n(e){let t='
",t}function s(e){let n=e.filter.currentValue||e.filter.defaultValue,t='${e.filter.label}
`,e.filter.options.forEach(s=>{let o=s.id===n;t+=``}),t+="${e.filter.label}
`,t+=`account_id
Type: STRING
action_plan_instructions
Type: STRING
Provider name: actionPlanInstructions
Description: The recommended actions to carry out if the control isn’t fulfilled.
action_plan_title
Type: STRING
Provider name: actionPlanTitle
Description: The title of the action plan for remediating the control.
arn
Type: STRING
Provider name: arn
Description: The Amazon Resource Name (ARN) of the control.
control_mapping_sources
Type: UNORDERED_LIST_STRUCT
Provider name: controlMappingSources
Description: The data mapping sources for the control.
source_description
STRING
sourceDescription
source_frequency
STRING
sourceFrequency
source_id
STRING
sourceId
source_keyword
STRUCT
sourceKeyword
keyword_input_type
STRING
keywordInputType
SELECT_FROM_LIST
is used when mapping a data source for automated evidence.keywordInputType
is SELECT_FROM_LIST
, a keyword must be selected to collect automated evidence. For example, this keyword can be a CloudTrail event name, a rule name for Config, a Security Hub control, or the name of an Amazon Web Services API call.UPLOAD_FILE
and INPUT_TEXT
are only used when mapping a data source for manual evidence.keywordInputType
is UPLOAD_FILE
, a file must be uploaded as manual evidence.keywordInputType
is INPUT_TEXT
, text must be entered as manual evidence.keyword_value
STRING
keywordValue
keywordValue
that you specify depends on the type of rule:keywordValue
. You can find the rule identifier from the list of Config managed rules. For some rules, the rule identifier is different from the rule name. For example, the rule name restricted-ssh
has the following rule identifier: INCOMING_SSH_DISABLED
. Make sure to use the rule identifier, not the rule name. Keyword example for managed rules:keywordValue
: S3_BUCKET_ACL_PROHIBITED
keywordValue
by adding the Custom_
prefix to the rule name. This prefix distinguishes the custom rule from a managed rule. Keyword example for custom rules:keywordValue
: Custom_my-custom-config-rule
keywordValue
by adding the Custom_
prefix to the rule name. In addition, you remove the suffix ID that appears at the end of the rule name. Keyword examples for service-linked rules:keywordValue
: Custom_CustomRuleForAccount-conformance-pack
keywordValue
: Custom_OrgConfigRule-s3-bucket-versioning-enabled
keywordValue
is case sensitive. If you enter a value incorrectly, Audit Manager might not recognize the data source mapping. As a result, you might not successfully collect evidence from that data source as intended. Keep in mind the following requirements, depending on the data source type that you’re using.keywordValue
is the rule identifier in ALL_CAPS_WITH_UNDERSCORES
. For example, CLOUDWATCH_LOG_GROUP_ENCRYPTED
. For accuracy, we recommend that you reference the list of supported Config managed rules.keywordValue
has the Custom_
prefix followed by the custom rule name. The format of the custom rule name itself may vary. For accuracy, we recommend that you visit the Config console to verify your custom rule name.keywordValue
is written as serviceprefix_ActionName
. For example, iam_ListGroups
. For accuracy, we recommend that you reference the list of supported API calls.keywordValue
is written as serviceprefix_ActionName
. For example, cloudtrail_StartLogging
. For accuracy, we recommend that you review the Amazon Web Services service prefix and action names in the Service Authorization Reference.source_name
STRING
sourceName
source_set_up_option
STRING
sourceSetUpOption
sourceSetUpOption
, Audit Manager automatically infers and populates the correct value based on the sourceType
that you specify.source_type
STRING
sourceType
AWS_Cloudtrail
, AWS_Config
, AWS_Security_Hub
, AWS_API_Call
, or MANUAL
.Core_Control
or a Common_Control
.troubleshooting_text
STRING
troubleshootingText
control_sources
Type: STRING
Provider name: controlSources
Description: The data source types that determine where Audit Manager collects evidence from for the control.
created_at
Type: TIMESTAMP
Provider name: createdAt
Description: The time when the control was created.
created_by
Type: STRING
Provider name: createdBy
Description: The user or role that created the control.
description
Type: STRING
Provider name: description
Description: The description of the control.
id
Type: STRING
Provider name: id
Description: The unique identifier for the control.
last_updated_at
Type: TIMESTAMP
Provider name: lastUpdatedAt
Description: The time when the control was most recently updated.
last_updated_by
Type: STRING
Provider name: lastUpdatedBy
Description: The user or role that most recently updated the control.
name
Type: STRING
Provider name: name
Description: The name of the control.
state
Type: STRING
Provider name: state
Description: The state of the control. The END_OF_SUPPORT
state is applicable to standard controls only. This state indicates that the standard control can still be used to collect evidence, but Audit Manager is no longer updating or maintaining that control.
tags
Type: UNORDERED_LIST_STRING
testing_information
Type: STRING
Provider name: testingInformation
Description: The steps that you should follow to determine if the control has been satisfied.
type
Type: STRING
Provider name: type
Description: Specifies whether the control is a standard control or a custom control.