aws-controltower-enabled-control-parameter-value
Enabled-control parameter values are arbitrary documents and can include misplaced sensitive values.
Where it sits
| location | GetEnabledControl.enabledControlDetails.parameters[].value |
| location kind | config_field |
| data kinds | sensitive_data credential |
| emits edge | ContainsSecret |
| service | Control Tower (aws:controltower) |
Collection recipe
| access mode | read_api |
| operation | GetEnabledControl |
| response path | enabledControlDetails.parameters[].value |
| encoding | json |
| params | {"enabledControlIdentifier": "\u003cenabled-control-arn\u003e"} |
Required permissions
controltower:GetEnabledControl
References