View a markdown version of this page

Actions, resources, and condition keys for AWS Security Incident Response - Service Authorization Reference

Actions, resources, and condition keys for AWS Security Incident Response

AWS Security Incident Response (service prefix: security-ir) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Security Incident Response

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

BatchGetMemberAccountDetails

security-ir:BatchGetMemberAccountDetails

Read

CancelMembership

security-ir:CancelMembership

Write

CloseCase

security-ir:CloseCase

Write

CreateCase

security-ir:CreateCase

Write

security-ir:TagResource

Tagging, Write

CreateCaseComment

security-ir:CreateCaseComment

Write

CreateMembership

security-ir:CreateMembership

Write

security-ir:TagResource

Tagging, Write

GetCase

security-ir:GetCase

Read

GetCaseAttachmentDownloadUrl

security-ir:GetCaseAttachmentDownloadUrl

Read

GetCaseAttachmentUploadUrl

security-ir:GetCaseAttachmentUploadUrl

Write

GetMembership

security-ir:GetMembership

Read

ListCaseEdits

security-ir:ListCaseEdits

Read

ListCases

security-ir:ListCases

List

ListComments

security-ir:ListComments

Read

ListInvestigations

security-ir:ListInvestigations

Read

ListMemberships

security-ir:ListMemberships

List

ListTagsForResource

security-ir:ListTagsForResource

Read

SendFeedback

security-ir:SendFeedback

Write

TagResource

security-ir:TagResource

Tagging, Write

UntagResource

security-ir:UntagResource

Tagging, Write

UpdateCase

security-ir:UpdateCase

Write

UpdateCaseComment

security-ir:UpdateCaseComment

Write

UpdateCaseStatus

security-ir:UpdateCaseStatus

Write

UpdateMembership

security-ir:UpdateMembership

Write

UpdateResolverType

security-ir:UpdateResolverType

Write

Actions defined by AWS Security Incident Response

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

BatchGetMemberAccountDetails

Grants permission to get member account details in batch

membership*

aws:ResourceTag/${TagKey}

Read