Skip to content

aws.auditmanager.list_control_domain_insights_by_assessment

Example SQL Queries

SELECT * FROM
aws.auditmanager.list_control_domain_insights_by_assessment
WHERE
"assessment_id" = 'VALUE';

Description

Lists analytics data for control domains within a specified active assessment.

Audit Manager supports the control domains that are provided by Amazon Web Services Control Catalog. For information about how to find a list of available control domains, see ListDomains in the Amazon Web Services Control Catalog API Reference.

A control domain is listed only if at least one of the controls within that domain collected evidence on the lastUpdated date of controlDomainInsights. If this condition isn’t met, no data is listed for that domain.

Table Definition

Column NameColumn Data Type
assessment_id Required Input Column

The unique identifier for the active assessment.

VARCHAR
max_results Input Column

Represents the maximum number of results on a page or for an API request call.

BIGINT
next_token Input Column

The pagination token that's used to fetch the next set of results.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
control_domain_insights

The control domain analytics data that the ListControlDomainInsightsByAssessment API returned.

STRUCT(
"name" VARCHAR,
"id" VARCHAR,
"controls_count_by_noncompliant_evidence" BIGINT,
"total_controls_count" BIGINT,
"evidence_insights" STRUCT(
"noncompliant_evidence_count" BIGINT,
"compliant_evidence_count" BIGINT,
"inconclusive_evidence_count" BIGINT
),
"last_updated" TIMESTAMP_S
)[]
Show child fields
control_domain_insights[]
Show child fields
control_domain_insights[].controls_count_by_noncompliant_evidence

The number of controls in the control domain that collected non-compliant evidence on the lastUpdated date.

control_domain_insights[].evidence_insights

A breakdown of the compliance check status for the evidence that’s associated with the control domain.

Show child fields
control_domain_insights[].evidence_insights.compliant_evidence_count

The number of compliance check evidence that Audit Manager classified as compliant. This includes evidence that was collected from Security Hub with a Pass ruling, or collected from Config with a Compliant ruling.

control_domain_insights[].evidence_insights.inconclusive_evidence_count

The number of evidence that a compliance check ruling isn't available for. Evidence is inconclusive when the associated control uses Security Hub or Config as a data source but you didn't enable those services. This is also the case when a control uses a data source that doesn’t support compliance checks (for example, manual evidence, API calls, or CloudTrail).

If evidence has a compliance check status of not applicable in the console, it's classified as inconclusive in EvidenceInsights data.

control_domain_insights[].evidence_insights.noncompliant_evidence_count

The number of compliance check evidence that Audit Manager classified as non-compliant. This includes evidence that was collected from Security Hub with a Fail ruling, or collected from Config with a Non-compliant ruling.

control_domain_insights[].id

The unique identifier for the control domain. Audit Manager supports the control domains that are provided by Amazon Web Services Control Catalog. For information about how to find a list of available control domains, see ListDomains in the Amazon Web Services Control Catalog API Reference.

control_domain_insights[].last_updated

The time when the control domain insights were last updated.

control_domain_insights[].name

The name of the control domain.

control_domain_insights[].total_controls_count

The total number of controls in the control domain.