Skip to content

aws.securityhub.get_configuration_policy

Example SQL Queries

SELECT * FROM
aws.securityhub.get_configuration_policy
WHERE
"identifier" = 'VALUE';

Description

Provides information about a configuration policy. Only the Security Hub delegated administrator can invoke this operation from the home Region.

Table Definition

Column NameColumn Data Type
identifier Required Input Column

The Amazon Resource Name (ARN) or universally unique identifier (UUID) of the configuration policy.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
arn

The ARN of the configuration policy.

VARCHAR
configuration_policy

An object that defines how Security Hub is configured. It includes whether Security Hub is enabled or disabled, a list of enabled security standards, a list of enabled or disabled security controls, and a list of custom parameter values for specified controls. If the policy includes a list of security controls that are enabled, Security Hub disables all other controls (including newly released controls). If the policy includes a list of security controls that are disabled, Security Hub enables all other controls (including newly released controls).

STRUCT(
"security_hub" STRUCT(
"service_enabled" BOOLEAN,
"enabled_standard_identifiers" VARCHAR[],
"security_controls_configuration" STRUCT(
"enabled_security_control_identifiers" VARCHAR[],
"disabled_security_control_identifiers" VARCHAR[],
"security_control_custom_parameters" STRUCT(
"security_control_id" VARCHAR,
"parameters" MAP(VARCHAR, STRUCT(
"value_type" VARCHAR,
"value" STRUCT(
"integer" BIGINT,
"integer_list" BIGINT[],
"double" DOUBLE,
"string" VARCHAR,
"string_list" VARCHAR[],
"boolean" BOOLEAN,
"enum" VARCHAR,
"enum_list" VARCHAR[]
)
))
)[]
)
)
)
Show child fields
configuration_policy.security_hub

The Amazon Web Servicesservice that the configuration policy applies to.

Show child fields
configuration_policy.security_hub.enabled_standard_identifiers[]
configuration_policy.security_hub.security_controls_configuration

An object that defines which security controls are enabled in the configuration policy. The enablement status of a control is aligned across all of the enabled standards in an account.

Show child fields
configuration_policy.security_hub.security_controls_configuration.disabled_security_control_identifiers[]
configuration_policy.security_hub.security_controls_configuration.enabled_security_control_identifiers[]
configuration_policy.security_hub.security_controls_configuration.security_control_custom_parameters[]
Show child fields
configuration_policy.security_hub.security_controls_configuration.security_control_custom_parameters[].parameters

An object that specifies parameter values for a control in a configuration policy.

configuration_policy.security_hub.security_controls_configuration.security_control_custom_parameters[].security_control_id

The ID of the security control.

configuration_policy.security_hub.service_enabled

Indicates whether Security Hub is enabled in the policy.

created_at

The date and time, in UTC and ISO 8601 format, that the configuration policy was created.

TIMESTAMP_S
description

The description of the configuration policy.

VARCHAR
id

The UUID of the configuration policy.

VARCHAR
name

The name of the configuration policy.

VARCHAR
updated_at

The date and time, in UTC and ISO 8601 format, that the configuration policy was last updated.

TIMESTAMP_S