Actions, resources, and condition keys for AWS Network Security Manager
AWS Network Security Manager (service prefix: network-security-manager) provides the following
service-specific operations, resources, actions, and condition keys for use in IAM permission
policies.
References:
-
Learn how to configure this service.
-
View a list of the API operations available for this service.
-
Learn how to secure this service and its resources by using IAM permission policies.
-
View the programmatic service authorization reference
for this service.
Topics
API operations defined by AWS Network Security Manager
The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.
| Operation | IAM action | Condition key | Possible value(s) | Access level |
|---|---|---|---|---|
|
CreateDeployment |
Write |
|||
Tagging, Write |
||||
|
CreateDeploymentSnapshot |
Write |
|||
Tagging, Write |
||||
|
CreatePolicy |
Write |
|||
Tagging, Write |
||||
|
CreatePolicySnapshot |
Write |
|||
Tagging, Write |
||||
|
CreateRule |
Write |
|||
Tagging, Write |
||||
|
CreateRuleSnapshot |
Write |
|||
Tagging, Write |
||||
|
CreateScope |
Write |
|||
Tagging, Write |
||||
|
CreateScopeSnapshot |
Write |
|||
Tagging, Write |
||||
|
CreateTemplate |
Write |
|||
Tagging, Write |
||||
|
CreateTemplateSnapshot |
Write |
|||
Tagging, Write |
||||
|
DeleteAdminAccount |
Write |
|||
|
DeleteDeployment |
Write |
|||
|
DeletePolicy |
Write |
|||
|
DeleteRule |
Write |
|||
|
DeleteScope |
Write |
|||
|
DeleteTemplate |
Write |
|||
|
GenerateRuleConfiguration |
Write |
|||
|
GetAdminAccount |
Read |
|||
|
GetDeployment |
Read |
|||
|
GetPolicy |
Read |
|||
|
GetRule |
Read |
|||
|
GetScope |
Read |
|||
|
GetTemplate |
Read |
|||
|
ListAdminAccounts |
List |
|||
|
ListAggregateResourceSynchronizationStatuses |
network-security-manager:ListAggregateResourceSynchronizationStatuses |
Read |
||
|
ListDeploymentSnapshots |
Read |
|||
|
ListDeployments |
List |
|||
|
ListPolicies |
List |
|||
|
ListPolicySnapshots |
Read |
|||
|
ListResourceAssociations |
Read |
|||
|
ListResourceSynchronizationStatuses |
network-security-manager:ListResourceSynchronizationStatuses |
Read |
||
|
ListRuleSnapshots |
Read |
|||
|
ListRules |
List |
|||
|
ListScopeSnapshots |
Read |
|||
|
ListScopes |
List |
|||
|
ListTagsForResource |
Read |
|||
|
ListTemplateSnapshots |
Read |
|||
|
ListTemplates |
List |
|||
|
PutAdminAccount |
Write |
|||
|
TagResource |
Tagging, Write |
|||
|
UntagResource |
Tagging, Write |
|||
|
UpdateDeployment |
Write |
|||
|
UpdatePolicy |
Write |
|||
|
UpdateRule |
Write |
|||
|
UpdateScope |
Write |
|||
|
UpdateTemplate |
Write |
Actions defined by AWS Network Security Manager
You can specify the following actions in the Action element of an IAM
policy statement. Use policies to grant permissions to perform an operation in AWS. When
you use an action in a policy, you usually allow or deny access to the API operation or CLI
command with the same name. However, in some cases, a single action controls access to more
than one operation. Alternatively, some operations require several different actions.
| Actions | Description | Resource types (*required) | Condition keys | Access level |
|---|---|---|---|---|
Grants permission to create a deployment |
Write |
|||
Grants permission to create a snapshot of a deployment |
Write |
|||
Grants permission to create a policy |
Write |
|||
Grants permission to create a snapshot of a policy |
Write |
|||
Grants permission to create a rule |
Write |
|||
Grants permission to create a snapshot of a rule |
Write |
|||
Grants permission to create a scope |
Write |
|||
Grants permission to create a snapshot of a scope |
Write |
|||
Grants permission to create a template |
Write |
|||
Grants permission to create a snapshot of a template |
Write |
|||
Grants permission to remove a Network Security Manager administrator account |
Write |
|||
Grants permission to delete a deployment |
Write |
|||
Grants permission to delete a policy |
Write |
|||
Grants permission to delete a rule |
Write |
|||
Grants permission to delete a scope |
Write |
|||
Grants permission to delete a template |
Write |
|||
Grants permission to generate a rule configuration from a natural-language prompt |
Write |
|||
Grants permission to retrieve a Network Security Manager administrator account |
Read |
|||
Grants permission to retrieve a deployment |
Read |
|||
Grants permission to retrieve a policy |
Read |
|||
Grants permission to retrieve a rule |
Read |
|||
Grants permission to retrieve a scope |
Read |
|||
Grants permission to retrieve a template |
Read |
|||
Grants permission to list Network Security Manager administrator accounts |
List |
|||
Grants permission to list aggregate resource synchronization statuses across the caller's deployments |
Read |
|||
Grants permission to list the snapshots of a deployment |
Read |
|||
Grants permission to list deployments |
List |
|||
Grants permission to list policies |
List |
|||
Grants permission to list the snapshots of a policy |
Read |
|||
Grants permission to list the associations of a Network Security Manager resource |
Read |
|||
Grants permission to list resource synchronization statuses for a deployment |
Read |
|||
Grants permission to list the snapshots of a rule |
Read |
|||
Grants permission to list rules |
List |
|||
Grants permission to list the snapshots of a scope |
Read |
|||
Grants permission to list scopes |
List |
|||
Grants permission to list the tags of a Network Security Manager resource |
Read |
|||
Grants permission to list the snapshots of a template |
Read |
|||
Grants permission to list templates |
List |
|||
Grants permission to set a Network Security Manager administrator account |
Write |
|||
Grants permission to add or overwrite tags on a Network Security Manager resource |
Tagging, Write |
|||
Grants permission to remove tags from a Network Security Manager resource |
Tagging, Write |
|||
Grants permission to update a deployment |
Write |
|||
Grants permission to update a policy |
Write |
|||
Grants permission to update a rule |
Write |
|||
Grants permission to update a scope |
Write |
|||
Grants permission to update a template |
Write |
|||
Resource types defined by AWS Network Security Manager
The following resource types are defined by this service and can be used in the
Resource element of IAM permission policy statements.
| Resource types | ARN | Condition keys |
|---|---|---|
arn:${Partition}:network-security-manager:${Region}:${Account}:deployment:${DeploymentId} |
||
arn:${Partition}:network-security-manager:${Region}:${Account}:deployment:${DeploymentId}:${VersionNumber} |
||
arn:${Partition}:network-security-manager:${Region}:${Account}:policy:${PolicyId} |
||
arn:${Partition}:network-security-manager:${Region}:${Account}:policy:${PolicyId}:${VersionNumber} |
||
arn:${Partition}:network-security-manager:${Region}:${Account}:rule:${RuleId} |
||
arn:${Partition}:network-security-manager:${Region}:${Account}:rule:${RuleId}:${VersionNumber} |
||
arn:${Partition}:network-security-manager:${Region}:${Account}:scope:${ScopeId} |
||
arn:${Partition}:network-security-manager:${Region}:${Account}:scope:${ScopeId}:${VersionNumber} |
||
arn:${Partition}:network-security-manager:${Region}:${Account}:template:${TemplateId} |
||
arn:${Partition}:network-security-manager:${Region}:${Account}:template:${TemplateId}:${VersionNumber} |
Condition keys for AWS Network Security Manager
AWS Network Security Manager defines the following condition keys that can be used in the
Condition element of an IAM policy.
| Condition keys | Description | Type |
|---|---|---|
Filters access by the tags that are passed in the request |
String |
|
Filters access by the tags associated with the resource |
String |
|
Filters access by the tag keys that are passed in the request |
ArrayOfString |