Amazon Web Services connector user permissions and imported data
The dynamic attributes connector imports dynamic attributes from Amazon Web Services (AWS) to Security Cloud Control for use in policies.
Dynamic attributes imported
The connector imports these dynamic attributes from AWS:
-
Tags, user-defined key-value pairs you can use to organize your AWS EC2 resources.
For more information, see Tag your EC2 Resources in the AWS documentation
-
IP addresses of virtual machines in AWS.
Minimum permissions required
The dynamic attributes connector requires a user at minimum with a policy that permits ec2:DescribeTags, ec2:DescribeVpcs, and ec2:DescribeInstances to be able to import dynamic attributes.