AWS Firewall Manager (fms)

2022-12-15

8 new actions, 1 new resource | 2 updated actions

Additions

    Actions
  • BatchAssociateResource
    • Description:  Grants permission to associate resources to an AWS Firewall Manager resource set
    • Access:  Write
    • Resources: 

      Name: resource-set

      Required: Yes

  • BatchDisassociateResource
    • Description:  Grants permission to disassociate resources from an AWS Firewall Manager resource set
    • Access:  Write
    • Resources: 

      Name: resource-set

      Required: Yes

  • DeleteResourceSet
    • Description:  Grants permission to permanently delete an AWS Firewall Manager resource set
    • Access:  Write
    • Resources: 

      Name: resource-set

      Required: Yes

    • Conditions: 

      aws:ResourceTag/${TagKey}

  • GetResourceSet
    • Description:  Grants permission to retrieve information about the specified AWS Firewall Manager resource set
    • Access:  Read
    • Resources: 

      Name: resource-set

      Required: Yes

  • ListDiscoveredResources
    • Description:  Grants permission to retrieve an array of resources in the organization's accounts that are available to be associated with a resource set
    • Access:  List
  • ListResourceSetResources
    • Description:  Grants permission to retrieve an array of resources that are currently associated to a resource set
    • Access:  List
    • Resources: 

      Name: resource-set

      Required: Yes

  • ListResourceSets
    • Description:  Grants permission to retrieve an array of ResourceSetSummary objects
    • Access:  List
  • PutResourceSet
    • Description:  Grants permission to create an AWS Firewall Manager resource set
    • Access:  Write
    • Resources: 

      Name: resource-set

      Required: Yes

    • Conditions: 

      aws:RequestTag/${TagKey}

      aws:TagKeys

    Resources
  • resource-set
    • Arn:  arn:${Partition}:fms:${Region}:${Account}:resource-set/${Id}
    • Conditions: 

      aws:ResourceTag/${TagKey}

Updates

    Actions
  • TagResource
      Resources
    • New_value: No

      Old_value: Yes

    • + applications-list
    • + protocols-list
    • + resource-set
  • UntagResource
      Resources
    • New_value: No

      Old_value: Yes

    • + applications-list
    • + protocols-list
    • + resource-set