{
  "url": "https://docs.aws.amazon.com/service-authorization/latest/reference/list_awssecurityhub.html",
  "name": "AWS Security Hub",
  "prefix": "securityhub",
  "timestamp": "1775779207",
  "actions": [
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_AcceptAdministratorInvitation.html",
      "name": "AcceptAdministratorInvitation",
      "description": "Grants permission to accept Security Hub invitations to become a member account",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_AcceptInvitation.html",
      "name": "AcceptInvitation",
      "description": "Grants permission to accept Security Hub invitations to become a member account",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_AllowVendedLogDeliveryForResource.html",
      "name": "AllowVendedLogDeliveryForResource",
      "description": "Grants permission to log delivery for resources",
      "access": "Permissions management",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        },
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "BatchDeleteAutomationRules",
      "description": "Grants permission to delete one or more automation rules in Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "automation-rule",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchDisableStandards.html",
      "name": "BatchDisableStandards",
      "description": "Grants permission to disable standards in Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchEnableStandards.html",
      "name": "BatchEnableStandards",
      "description": "Grants permission to enable standards in Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "BatchGetAutomationRules",
      "description": "Grants permission to retrieve a list of details for automation rules from Security Hub based on rule Amazon Resource Names (ARNs)",
      "access": "Read",
      "resources": [
        {
          "name": "automation-rule",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchGetConfigurationPolicyAssociations.html",
      "name": "BatchGetConfigurationPolicyAssociations",
      "description": "Grants permission to retrieve information about configuration policies associated with a specific list of member accounts and organizational units of the calling account's organization",
      "access": "Read",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/iam-permissions-controls-standards.html",
      "name": "BatchGetControlEvaluations",
      "description": "Grants permission to get the enablement and compliance status of controls, the findings count for controls, and the overall security score for controls on the Security Hub console",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchGetSecurityControls.html",
      "name": "BatchGetSecurityControls",
      "description": "Grants permission to get details about specific security controls identified by ID or ARN",
      "access": "Read",
      "resources": [],
      "conditions": [],
      "dependents": [
        "securityhub:DescribeStandardsControls"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchGetStandardsControlAssociations.html",
      "name": "BatchGetStandardsControlAssociations",
      "description": "Grants permission to get the enablement status of a batch of security controls in standards",
      "access": "Read",
      "resources": [],
      "conditions": [],
      "dependents": [
        "securityhub:DescribeStandardsControls"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchImportFindings.html",
      "name": "BatchImportFindings",
      "description": "Grants permission to import findings into Security Hub from an integrated product",
      "access": "Write",
      "resources": [
        {
          "name": "product",
          "is_required": true
        }
      ],
      "conditions": [
        "securityhub:TargetAccount"
      ],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "BatchUpdateAutomationRules",
      "description": "Grants permission to update one or more automation rules from Security Hub based on rule Amazon Resource Names (ARNs) and input parameters",
      "access": "Write",
      "resources": [
        {
          "name": "automation-rule",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchUpdateFindingsV2.html",
      "name": "BatchUpdateFindings",
      "description": "Grants permission to update customer-controlled fields for a selected set of Security Hub findings",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        },
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [
        "securityhub:ASFFSyntaxPath/${ASFFSyntaxPath}",
        "securityhub:OCSFSyntaxPath/${OCSFSyntaxPath}"
      ],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_BatchUpdateStandardsControlAssociations.html",
      "name": "BatchUpdateStandardsControlAssociations",
      "description": "Grants permission to update the enablement status of a batch of security controls in standards",
      "access": "Write",
      "resources": [],
      "conditions": [],
      "dependents": [
        "securityhub:UpdateStandardsControl"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ConnectorRegistrationsV2.html",
      "name": "ConnectorRegistrationsV2",
      "description": "Grants permission to complete the OAuth 2.0 authorization code flow based on input parameters",
      "access": "Write",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateActionTarget.html",
      "name": "CreateActionTarget",
      "description": "Grants permission to create custom actions in Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateAggregatorV2.html",
      "name": "CreateAggregatorV2",
      "description": "Grants permission to create an aggregatorV2, which configures data aggregation across Regions",
      "access": "Write",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "CreateAutomationRule",
      "description": "Grants permission to create an automation rule based on input parameters",
      "access": "Write",
      "resources": [],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "CreateAutomationRuleV2",
      "description": "Grants permission to create an automation rule V2 based on input parameters",
      "access": "Write",
      "resources": [],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateConfigurationPolicy.html",
      "name": "CreateConfigurationPolicy",
      "description": "Grants permission to create a configuration policy to manage organization member settings in Security Hub",
      "access": "Write",
      "resources": [],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateConnectorV2.html",
      "name": "CreateConnectorV2",
      "description": "Grants permission to create a connector V2 based on input parameters",
      "access": "Write",
      "resources": [],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateFindingAggregator.html",
      "name": "CreateFindingAggregator",
      "description": "Grants permission to create a finding aggregator, which contains the cross-Region finding aggregation configuration",
      "access": "Write",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateInsight.html",
      "name": "CreateInsight",
      "description": "Grants permission to create insights in Security Hub. Insights are collections of related findings",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateMembers.html",
      "name": "CreateMembers",
      "description": "Grants permission to create member accounts in Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_CreateTicketV2.html",
      "name": "CreateTicketV2",
      "description": "Grants permission to create ticket for a selected OCSF finding",
      "access": "Write",
      "resources": [
        {
          "name": "connectorv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeclineInvitations.html",
      "name": "DeclineInvitations",
      "description": "Grants permission to decline Security Hub invitations to become a member account",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteActionTarget.html",
      "name": "DeleteActionTarget",
      "description": "Grants permission to delete custom actions in Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteAggregatorV2.html",
      "name": "DeleteAggregatorV2",
      "description": "Grants permission to delete an aggregatorV2, which configures data aggregation across Regions",
      "access": "Write",
      "resources": [
        {
          "name": "aggregatorv2",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "DeleteAutomationRuleV2",
      "description": "Grants permission to delete an automation rule V2 in Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "automation-rulev2",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteConfigurationPolicy.html",
      "name": "DeleteConfigurationPolicy",
      "description": "Grants permission to delete an existing configuration policy",
      "access": "Write",
      "resources": [
        {
          "name": "configuration-policy",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteConnectorV2.html",
      "name": "DeleteConnectorV2",
      "description": "Grants permission to delete a connector V2 in Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "connectorv2",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteFindingAggregator.html",
      "name": "DeleteFindingAggregator",
      "description": "Grants permission to delete a finding aggregator, which disables finding aggregation across Regions",
      "access": "Write",
      "resources": [
        {
          "name": "finding-aggregator",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteInsight.html",
      "name": "DeleteInsight",
      "description": "Grants permission to delete insights from Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteInvitations.html",
      "name": "DeleteInvitations",
      "description": "Grants permission to delete Security Hub invitations to become a member account",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DeleteMembers.html",
      "name": "DeleteMembers",
      "description": "Grants permission to delete Security Hub member accounts",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeActionTargets.html",
      "name": "DescribeActionTargets",
      "description": "Grants permission to retrieve a list of custom actions using the API",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeHub.html",
      "name": "DescribeHub",
      "description": "Grants permission to retrieve information about the hub resource in your account",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeOrganizationConfiguration.html",
      "name": "DescribeOrganizationConfiguration",
      "description": "Grants permission to describe the organization configuration for Security Hub",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeProducts.html",
      "name": "DescribeProducts",
      "description": "Grants permission to retrieve information about the available Security Hub product integrations",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeProductsV2.html",
      "name": "DescribeProductsV2",
      "description": "Grants permission to retrieve information about the available Security Hub V2 product integrations",
      "access": "Read",
      "resources": [
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeSecurityHubV2.html",
      "name": "DescribeSecurityHubV2",
      "description": "Grants permission to retrieve information about the hub V2 resource in your account",
      "access": "Read",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeStandards.html",
      "name": "DescribeStandards",
      "description": "Grants permission to retrieve information about Security Hub standards",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DescribeStandardsControls.html",
      "name": "DescribeStandardsControls",
      "description": "Grants permission to retrieve information about Security Hub standards controls",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisableImportFindingsForProduct.html",
      "name": "DisableImportFindingsForProduct",
      "description": "Grants permission to disable the findings importing for a Security Hub integrated product",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisableOrganizationAdminAccount.html",
      "name": "DisableOrganizationAdminAccount",
      "description": "Grants permission to remove the Security Hub administrator account for your organization",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": [
        "organizations:DeregisterDelegatedAdministrator",
        "organizations:DescribeOrganization",
        "organizations:ListDelegatedAdministrators"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisableSecurityHub.html",
      "name": "DisableSecurityHub",
      "description": "Grants permission to disable Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisableSecurityHubV2.html",
      "name": "DisableSecurityHubV2",
      "description": "Grants permission to disable Security Hub V2",
      "access": "Write",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisassociateFromAdministratorAccount.html",
      "name": "DisassociateFromAdministratorAccount",
      "description": "Grants permission to a Security Hub member account to disassociate from the associated administrator account",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisassociateFromMasterAccount.html",
      "name": "DisassociateFromMasterAccount",
      "description": "Grants permission to a Security Hub member account to disassociate from the associated master account",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_DisassociateMembers.html",
      "name": "DisassociateMembers",
      "description": "Grants permission to disassociate Security Hub member accounts from the associated administrator account",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_EnableImportFindingsForProduct.html",
      "name": "EnableImportFindingsForProduct",
      "description": "Grants permission to enable the findings importing for a Security Hub integrated product",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_EnableOrganizationAdminAccount.html",
      "name": "EnableOrganizationAdminAccount",
      "description": "Grants permission to designate a Security Hub administrator account for your organization",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": [
        "organizations:DescribeOrganization",
        "organizations:EnableAWSServiceAccess",
        "organizations:ListAWSServiceAccessForOrganization",
        "organizations:ListDelegatedAdministrators",
        "organizations:RegisterDelegatedAdministrator"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_EnableSecurityHub.html",
      "name": "EnableSecurityHub",
      "description": "Grants permission to enable Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_EnableSecurityHubV2.html",
      "name": "EnableSecurityHubV2",
      "description": "Grants permission to enable Security Hub V2",
      "access": "Write",
      "resources": [],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFindingStatisticsV2.html",
      "name": "GetAdhocInsightResults",
      "description": "Grants permission to retrieve aggregated statistical data about the findings",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        },
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetAdministratorAccount.html",
      "name": "GetAdministratorAccount",
      "description": "Grants permission to retrieve details about the Security Hub administrator account",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetAggregatorV2.html",
      "name": "GetAggregatorV2",
      "description": "Grants permission to retrieve details for an aggregatorV2, which configures data aggregation across Regions",
      "access": "Read",
      "resources": [
        {
          "name": "aggregatorv2",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "GetAutomationRuleV2",
      "description": "Grants permission to retrieve details for an automation rule V2 from Security Hub based on rule Amazon Resource Name (ARN)",
      "access": "Read",
      "resources": [
        {
          "name": "automation-rulev2",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetConfigurationPolicy.html",
      "name": "GetConfigurationPolicy",
      "description": "Grants permission to get a complete overview of one configuration policy created by the calling account",
      "access": "Read",
      "resources": [
        {
          "name": "configuration-policy",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetConfigurationPolicyAssociation.html",
      "name": "GetConfigurationPolicyAssociation",
      "description": "Grants permission to retrieve information about a configuration policy associated with a member account or organizational unit of the calling account's organization",
      "access": "Read",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetConnectorV2.html",
      "name": "GetConnectorV2",
      "description": "Grants permission to retrieve details for a connector V2 from Security Hub based on connector id",
      "access": "Read",
      "resources": [
        {
          "name": "connectorv2",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetControlFindingSummary.html",
      "name": "GetControlFindingSummary",
      "description": "Grants permission to retrieve a security score and counts of finding and control statuses for a security standard",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetEnabledStandards.html",
      "name": "GetEnabledStandards",
      "description": "Grants permission to retrieve a list of the standards that are enabled in Security Hub",
      "access": "List",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFindingAggregator.html",
      "name": "GetFindingAggregator",
      "description": "Grants permission to retrieve details for a finding aggregator, which configures finding aggregation across Regions",
      "access": "Read",
      "resources": [
        {
          "name": "finding-aggregator",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFindingHistory.html",
      "name": "GetFindingHistory",
      "description": "Grants permission to retrieve a list of finding history from Security Hub",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFindingsV2.html",
      "name": "GetFindings",
      "description": "Grants permission to retrieve a list of findings from Security Hub",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        },
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFindingsTrendsV2.html",
      "name": "GetFindingsTrendsV2",
      "description": "Grants permission to retrieve findings trends",
      "access": "Read",
      "resources": [
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFreeTrialEndDate.html",
      "name": "GetFreeTrialEndDate",
      "description": "Grants permission to retrieve the end date for an account's free trial of Security Hub",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetFreeTrialUsage.html",
      "name": "GetFreeTrialUsage",
      "description": "Grants permission to retrieve information about Security Hub usage during the free trial period",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetInsightFindingTrend.html",
      "name": "GetInsightFindingTrend",
      "description": "Grants permission to retrieve an insight finding trend from Security Hub in order to generate a graph",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetInsightResults.html",
      "name": "GetInsightResults",
      "description": "Grants permission to retrieve insight results from Security Hub",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetInsights.html",
      "name": "GetInsights",
      "description": "Grants permission to retrieve Security Hub insights",
      "access": "List",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetInvitationsCount.html",
      "name": "GetInvitationsCount",
      "description": "Grants permission to retrieve the count of Security Hub membership invitations sent to the account",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetMasterAccount.html",
      "name": "GetMasterAccount",
      "description": "Grants permission to retrieve details about the Security Hub master account",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetMembers.html",
      "name": "GetMembers",
      "description": "Grants permission to retrieve the details of Security Hub member accounts",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetResourcesStatisticsV2.html",
      "name": "GetResourcesStatisticsV2",
      "description": "Grants permission to retrieve aggregate statistics about resources",
      "access": "Read",
      "resources": [
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetResourcesTrendsV2.html",
      "name": "GetResourcesTrendsV2",
      "description": "Grants permission to retrieve resources trends",
      "access": "Read",
      "resources": [
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetResourcesV2.html",
      "name": "GetResourcesV2",
      "description": "Grants permission to retrieve a list of resources",
      "access": "Read",
      "resources": [
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetSecurityControlDefinition.html",
      "name": "GetSecurityControlDefinition",
      "description": "Grants permission to get the definition details of a specific security control identified by ID",
      "access": "Read",
      "resources": [],
      "conditions": [],
      "dependents": [
        "securityhub:DescribeStandardsControls"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_GetUsage.html",
      "name": "GetUsage",
      "description": "Grants permission to retrieve information about Security Hub usage by accounts",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_InviteMembers.html",
      "name": "InviteMembers",
      "description": "Grants permission to invite other AWS accounts to become Security Hub member accounts",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListAggregatorsV2.html",
      "name": "ListAggregatorsV2",
      "description": "Grants permission to retrieve a list of aggregatorsV2, which configures data aggregation across Regions",
      "access": "List",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "ListAutomationRules",
      "description": "Grants permission to retrieve a list of automation rules and their metadata for the calling account from Security Hub",
      "access": "List",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "ListAutomationRulesV2",
      "description": "Grants permission to retrieve a list of automation rules V2 and their metadata for the calling account from Security Hub",
      "access": "List",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListConfigurationPolicies.html",
      "name": "ListConfigurationPolicies",
      "description": "Grants permission to list the summaries of all configuration policies created by the calling account",
      "access": "List",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListConfigurationPolicyAssociations.html",
      "name": "ListConfigurationPolicyAssociations",
      "description": "Grants permission to retrieve information about all configuration policies associationed with all member accounts and organizational units of the calling account's organization",
      "access": "List",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListConnectorsV2.html",
      "name": "ListConnectorsV2",
      "description": "Grants permission to retrieve a list of connectors V2 and their metadata for the calling account from Security Hub",
      "access": "List",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListControlEvaluationSummaries.html",
      "name": "ListControlEvaluationSummaries",
      "description": "Grants permission to retrieve a list of controls for a standard, including the control IDs, statuses and finding counts",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListEnabledProductsForImport.html",
      "name": "ListEnabledProductsForImport",
      "description": "Grants permission to retrieve the Security Hub integrated products that are currently enabled",
      "access": "List",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListFindingAggregators.html",
      "name": "ListFindingAggregators",
      "description": "Grants permission to retrieve a list of finding aggregators, which contain the cross-Region finding aggregation configuration",
      "access": "List",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListInvitations.html",
      "name": "ListInvitations",
      "description": "Grants permission to retrieve the Security Hub invitations sent to the account",
      "access": "List",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListMembers.html",
      "name": "ListMembers",
      "description": "Grants permission to retrieve details about Security Hub member accounts associated with the administrator account",
      "access": "List",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListOrganizationAdminAccounts.html",
      "name": "ListOrganizationAdminAccounts",
      "description": "Grants permission to list the Security Hub administrator accounts for your organization",
      "access": "List",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": [
        "organizations:DescribeOrganization",
        "organizations:ListDelegatedAdministrators"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListSecurityControlDefinitions.html",
      "name": "ListSecurityControlDefinitions",
      "description": "Grants permission to retrieve a list of security control definitions, which contain details for security controls in the current region",
      "access": "List",
      "resources": [],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListStandardsControlAssociations.html",
      "name": "ListStandardsControlAssociations",
      "description": "Grants permission to list the enablement status of a security control in standards",
      "access": "List",
      "resources": [],
      "conditions": [],
      "dependents": [
        "securityhub:DescribeStandardsControls"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_ListTagsForResource.html",
      "name": "ListTagsForResource",
      "description": "Grants permission to list of tags associated with a resource",
      "access": "Read",
      "resources": [
        {
          "name": "automation-rule",
          "is_required": false
        },
        {
          "name": "configuration-policy",
          "is_required": false
        },
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_SendFindingEvents.html",
      "name": "SendFindingEvents",
      "description": "Grants permission to use a custom action to send Security Hub findings to Amazon EventBridge",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_SendInsightEvents.html",
      "name": "SendInsightEvents",
      "description": "Grants permission to use a custom action to send Security Hub insights to Amazon EventBridge",
      "access": "Read",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_StartConfigurationPolicyAssociation.html",
      "name": "StartConfigurationPolicyAssociation",
      "description": "Grants permission to associate a configuration policy with a member account or organizational unit in the calling account's organization",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_StartConfigurationPolicyDisassociation.html",
      "name": "StartConfigurationPolicyDisassociation",
      "description": "Grants permission to remove a configuration policy association from a member account or organizational unit in the calling account's organization",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_TagResource.html",
      "name": "TagResource",
      "description": "Grants permission to add tags to a Security Hub resource",
      "access": "Tagging",
      "resources": [
        {
          "name": "aggregatorv2",
          "is_required": false
        },
        {
          "name": "automation-rule",
          "is_required": false
        },
        {
          "name": "automation-rulev2",
          "is_required": false
        },
        {
          "name": "configuration-policy",
          "is_required": false
        },
        {
          "name": "connectorv2",
          "is_required": false
        },
        {
          "name": "hub",
          "is_required": false
        },
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UntagResource.html",
      "name": "UntagResource",
      "description": "Grants permission to remove tags from a Security Hub resource",
      "access": "Tagging",
      "resources": [
        {
          "name": "aggregatorv2",
          "is_required": false
        },
        {
          "name": "automation-rule",
          "is_required": false
        },
        {
          "name": "automation-rulev2",
          "is_required": false
        },
        {
          "name": "configuration-policy",
          "is_required": false
        },
        {
          "name": "connectorv2",
          "is_required": false
        },
        {
          "name": "hub",
          "is_required": false
        },
        {
          "name": "hubv2",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateActionTarget.html",
      "name": "UpdateActionTarget",
      "description": "Grants permission to update custom actions in Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateAggregatorV2.html",
      "name": "UpdateAggregatorV2",
      "description": "Grants permission to update an aggregatorV2, which configures data aggregation across Regions",
      "access": "Write",
      "resources": [
        {
          "name": "aggregatorv2",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "UpdateAutomationRuleV2",
      "description": "Grants permission to update an automation rule V2 in Security Hub based on rule Amazon Resource Name (ARN) and input parameters",
      "access": "Write",
      "resources": [
        {
          "name": "automation-rulev2",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateConfigurationPolicy.html",
      "name": "UpdateConfigurationPolicy",
      "description": "Grants permission to update an existing configuration policy",
      "access": "Write",
      "resources": [
        {
          "name": "configuration-policy",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateConnectorV2.html",
      "name": "UpdateConnectorV2",
      "description": "Grants permission to update a connector V2 in Security Hub based on connector id and input parameters",
      "access": "Write",
      "resources": [
        {
          "name": "connectorv2",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateFindingAggregator.html",
      "name": "UpdateFindingAggregator",
      "description": "Grants permission to update a finding aggregator, which contains the cross-Region finding aggregation configuration",
      "access": "Write",
      "resources": [
        {
          "name": "finding-aggregator",
          "is_required": true
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateFindings.html",
      "name": "UpdateFindings",
      "description": "Grants permission to update Security Hub findings",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateInsight.html",
      "name": "UpdateInsight",
      "description": "Grants permission to update insights in Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateOrganizationConfiguration.html",
      "name": "UpdateOrganizationConfiguration",
      "description": "Grants permission to update the organization configuration for Security Hub",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateSecurityControl.html",
      "name": "UpdateSecurityControl",
      "description": "Grants permission to update properties of a specific security control identified by ID or ARN",
      "access": "Write",
      "resources": [],
      "conditions": [],
      "dependents": [
        "securityhub:UpdateStandardsControl"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateSecurityHubConfiguration.html",
      "name": "UpdateSecurityHubConfiguration",
      "description": "Grants permission to update Security Hub configuration",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/1.0/APIReference/API_UpdateStandardsControl.html",
      "name": "UpdateStandardsControl",
      "description": "Grants permission to update Security Hub standards controls",
      "access": "Write",
      "resources": [
        {
          "name": "hub",
          "is_required": false
        }
      ],
      "conditions": [],
      "dependents": []
    }
  ],
  "resources": [
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-access.html#resources",
      "name": "hub",
      "arn": "arn:${Partition}:securityhub:${Region}:${Account}:hub/default",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-access.html#resources",
      "name": "hubv2",
      "arn": "arn:${Partition}:securityhub:${Region}:${Account}:hubv2/${HubV2Id}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-access.html#resources",
      "name": "product",
      "arn": "arn:${Partition}:securityhub:${Region}:${Account}:product/${Company}/${ProductId}",
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-access.html#resources",
      "name": "finding-aggregator",
      "arn": "arn:${Partition}:securityhub:${Region}:${Account}:finding-aggregator/${FindingAggregatorId}",
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-access.html#resources",
      "name": "aggregatorv2",
      "arn": "arn:${Partition}:securityhub:${Region}:${Account}:aggregatorv2/${AggregatorV2Id}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "automation-rule",
      "arn": "arn:${Partition}:securityhub:${Region}:${Account}:automation-rule/${AutomationRuleId}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/automation-rules",
      "name": "automation-rulev2",
      "arn": "arn:${Partition}:securityhub:${Region}:${Account}:automation-rulev2/${AutomationRuleV2Id}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/central-configuration-intro.html",
      "name": "configuration-policy",
      "arn": "arn:${Partition}:securityhub:${Region}:${Account}:configuration-policy/${ConfigurationPolicyId}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-access.html#resources",
      "name": "connectorv2",
      "arn": "arn:${Partition}:securityhub:${Region}:${Account}:connectorv2/${ConnectorV2Id}",
      "conditions": [
        "aws:ResourceTag/${TagKey}"
      ]
    }
  ],
  "conditions": [
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-requesttag",
      "name": "aws:RequestTag/${TagKey}",
      "description": "Filters access by actions based on the presence of tag key-value pairs in the request",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-resourcetag",
      "name": "aws:ResourceTag/${TagKey}",
      "description": "Filters access by actions based on tag key-value pairs attached to the resource",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-tagkeys",
      "name": "aws:TagKeys",
      "description": "Filters access by actions based on the presence of tag keys in the request",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-asffsyntaxpath",
      "name": "securityhub:ASFFSyntaxPath/${ASFFSyntaxPath}",
      "description": "Filters access by the specified fields and values in the request",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-ocsfsyntaxpath",
      "name": "securityhub:OCSFSyntaxPath/${OCSFSyntaxPath}",
      "description": "Filters access by the specified fields and values in the request",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-access.html#conditions",
      "name": "securityhub:TargetAccount",
      "description": "Filters access by the AwsAccountId field that is specified in the request",
      "type": "String"
    }
  ]
}