import * as pulumi from "@pulumi/pulumi"; /** * Resource for managing an AWS Security Hub Standards Control Association. * * Disable/enable Security Hub security control in the standard. * * The `aws.securityhub.StandardsControlAssociation`, similarly to `aws.securityhub.StandardsControl`, * behaves differently from normal resources, in that Terraform does not _create_ this resource, but instead "adopts" it * into management. When you _delete_ this resource configuration, Terraform "abandons" resource as is and just removes it from the state. * * ## Example Usage * * ### Basic usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.securityhub.Account("example", {}); * const cisAwsFoundationsBenchmark = new aws.securityhub.StandardsSubscription("cis_aws_foundations_benchmark", {standardsArn: "arn:aws:securityhub:::ruleset/cis-aws-foundations-benchmark/v/1.2.0"}, { * dependsOn: [example], * }); * const cisAwsFoundationsBenchmarkDisableIam1 = new aws.securityhub.StandardsControlAssociation("cis_aws_foundations_benchmark_disable_iam_1", { * standardsArn: cisAwsFoundationsBenchmark.standardsArn, * securityControlId: "IAM.1", * associationStatus: "DISABLED", * updatedReason: "Not needed", * }); * ``` * * ### Disabling security control in all standards * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * export = async () => { * const example = new aws.securityhub.Account("example", {}); * const iam1 = await aws.securityhub.getStandardsControlAssociations({ * securityControlId: "IAM.1", * }); * const iam1StandardsControlAssociation: aws.securityhub.StandardsControlAssociation[] = []; * for (const range of Object.entries(.reduce((__obj, entry) => ({ ...__obj, [entry]: entry }), {})).sort().map(([k, v]) => ({key: k, value: v}))) { * iam1StandardsControlAssociation.push(new aws.securityhub.StandardsControlAssociation(`iam_1-${range.key}`, { * standardsArn: range.key, * securityControlId: iam1.securityControlId, * associationStatus: "DISABLED", * updatedReason: "Not needed", * })); * } * } * ``` * * ## Import * * ### Identity Schema * * #### Required * * * `securityControlId` (String) Security control ID. * * `standardsArn` (String) Standards ARN. * * #### Optional * * * `accountId` (String) AWS Account where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import Security Hub standards control associations using `securityControlId` and `standardsArn` separated by a comma (`,`). For example: * * ```sh * $ pulumi import aws:securityhub/standardsControlAssociation:StandardsControlAssociation example IAM.1,arn:aws:securityhub:us-east-1:123456789012:control/cis-aws-foundations-benchmark/v/1.2.0/1.10 * ``` */ export declare class StandardsControlAssociation extends pulumi.CustomResource { /** * Get an existing StandardsControlAssociation resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: StandardsControlAssociationState, opts?: pulumi.CustomResourceOptions): StandardsControlAssociation; /** * Returns true if the given object is an instance of StandardsControlAssociation. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is StandardsControlAssociation; /** * The desired enablement status of the control in the standard. Valid values: `ENABLED`, `DISABLED`. */ readonly associationStatus: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * The unique identifier for the security control whose enablement status you want to update. */ readonly securityControlId: pulumi.Output; /** * ARN of the standard in which you want to update the control's enablement status. * * The following arguments are optional: */ readonly standardsArn: pulumi.Output; /** * The reason for updating the control's enablement status in the standard. Required when `associationStatus` is `DISABLED`. */ readonly updatedReason: pulumi.Output; /** * Create a StandardsControlAssociation resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: StandardsControlAssociationArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering StandardsControlAssociation resources. */ export interface StandardsControlAssociationState { /** * The desired enablement status of the control in the standard. Valid values: `ENABLED`, `DISABLED`. */ associationStatus?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * The unique identifier for the security control whose enablement status you want to update. */ securityControlId?: pulumi.Input; /** * ARN of the standard in which you want to update the control's enablement status. * * The following arguments are optional: */ standardsArn?: pulumi.Input; /** * The reason for updating the control's enablement status in the standard. Required when `associationStatus` is `DISABLED`. */ updatedReason?: pulumi.Input; } /** * The set of arguments for constructing a StandardsControlAssociation resource. */ export interface StandardsControlAssociationArgs { /** * The desired enablement status of the control in the standard. Valid values: `ENABLED`, `DISABLED`. */ associationStatus: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * The unique identifier for the security control whose enablement status you want to update. */ securityControlId: pulumi.Input; /** * ARN of the standard in which you want to update the control's enablement status. * * The following arguments are optional: */ standardsArn: pulumi.Input; /** * The reason for updating the control's enablement status in the standard. Required when `associationStatus` is `DISABLED`. */ updatedReason?: pulumi.Input; } //# sourceMappingURL=standardsControlAssociation.d.ts.map