Skip to content

aws.controltower.get_enabled_control

Example SQL Queries

SELECT * FROM
aws.controltower.get_enabled_control
WHERE
"enabled_control_identifier" = 'VALUE';

Description

Retrieves details about an enabled control. For usage examples, see the Controls Reference Guide .

Table Definition

Column NameColumn Data Type
enabled_control_identifier Required Input Column

The controlIdentifier of the enabled control.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
enabled_control_details

Information about the enabled control.

STRUCT(
"arn" VARCHAR,
"control_identifier" VARCHAR,
"drift_status_summary" STRUCT(
"drift_status" VARCHAR
),
"parameters" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"status_summary" STRUCT(
"last_operation_identifier" VARCHAR,
"status" VARCHAR
),
"target_identifier" VARCHAR,
"target_regions" STRUCT(
"name" VARCHAR
)[]
)
Show child fields
enabled_control_details.arn

The ARN of the enabled control.

enabled_control_details.control_identifier

The control identifier of the enabled control. For information on how to find the controlIdentifier, see the overview page.

enabled_control_details.drift_status_summary

The drift status of the enabled control.

Show child fields
enabled_control_details.drift_status_summary.drift_status

The drift status of the enabled control.

Valid values:

  • DRIFTED: The enabledControl deployed in this configuration doesn’t match the configuration that Amazon Web Services Control Tower expected.

  • IN_SYNC: The enabledControl deployed in this configuration matches the configuration that Amazon Web Services Control Tower expected.

  • NOT_CHECKING: Amazon Web Services Control Tower does not check drift for this enabled control. Drift is not supported for the control type.

  • UNKNOWN: Amazon Web Services Control Tower is not able to check the drift status for the enabled control.

enabled_control_details.parameters[]
Show child fields
enabled_control_details.parameters[].key

The key of a key/value pair.

enabled_control_details.parameters[].value

The value of a key/value pair.

enabled_control_details.status_summary

The deployment summary of the enabled control.

Show child fields
enabled_control_details.status_summary.last_operation_identifier

The last operation identifier for the enabled resource.

enabled_control_details.status_summary.status

The deployment status of the enabled resource.

Valid values:

  • SUCCEEDED: The EnabledControl or EnabledBaseline configuration was deployed successfully.

  • UNDER_CHANGE: The EnabledControl or EnabledBaseline configuration is changing.

  • FAILED: The EnabledControl or EnabledBaseline configuration failed to deploy.

enabled_control_details.target_identifier

The ARN of the organizational unit. For information on how to find the targetIdentifier, see the overview page.

enabled_control_details.target_regions[]
Show child fields
enabled_control_details.target_regions[].name

The Amazon Web Services Region name.