Skip to content

Latest commit

 

History

History
30 lines (16 loc) · 1.99 KB

File metadata and controls

30 lines (16 loc) · 1.99 KB

List of queries

Query name: findings_iam_aa_external_access_org_boundary

Query description

List all active AWS IAM Access Analyzer external access findings with the organization as zone of trust. You can use this query to accelerate implementation of the identity perimeter controls on your resources. You can use the global condition key aws:PrincipalOrgId to limit access to your resources to principals belonging to your AWS organization.

Query name: findings_sh_external_access_org_boundary

Query description

This query extracts all AWS SecurityHub findings tied to IAM Access Analyzer external access findings with the organization as zone of trust. Note that (1) IAM Access Analyzer external access findings failing in error are not sent to SecurityHub and (2) IAM Access Analyzer external access findings in SecurityHub contains only one external principal even if the resource-based policy allows multiple principals. You can use this query to accelerate implementation of the identity perimeter controls on your resources. You can use the global condition key aws:PrincipalOrgId to limit access to your resources to principals belonging to your AWS organization.