View Source AWS.AuditManager (aws-elixir v0.13.3)

Welcome to the Audit Manager API reference.

This guide is for developers who need detailed information about the Audit Manager API operations, data types, and errors.

Audit Manager is a service that provides automated evidence collection so that you can continually audit your Amazon Web Services usage. You can use it to assess the effectiveness of your controls, manage risk, and simplify compliance.

Audit Manager provides prebuilt frameworks that structure and automate assessments for a given compliance standard. Frameworks include a prebuilt collection of controls with descriptions and testing procedures. These controls are grouped according to the requirements of the specified compliance standard or regulation. You can also customize frameworks and controls to support internal audits with specific requirements.

Use the following links to get started with the Audit Manager API:

* Actions: An alphabetical list of all Audit Manager API operations.

If you're new to Audit Manager, we recommend that you review the Audit Manager User Guide.

Link to this section Summary

Functions

Associates an evidence folder to an assessment report in an Audit Manager assessment.

Associates a list of evidence to an assessment report in an Audit Manager assessment.

Creates a batch of delegations for an assessment in Audit Manager.

Deletes a batch of delegations for an assessment in Audit Manager.

Disassociates a list of evidence from an assessment report in Audit Manager.

Uploads one or more pieces of evidence to a control in an Audit Manager assessment.

Creates an assessment in Audit Manager.

Creates a custom framework in Audit Manager.

Creates an assessment report for the specified assessment.

Creates a new custom control in Audit Manager.

Deletes an assessment in Audit Manager.

Deletes a share request for a custom framework in Audit Manager.

Deletes a custom control in Audit Manager.

Deregisters an account in Audit Manager.

Removes the specified Amazon Web Services account as a delegated administrator for Audit Manager.

Disassociates an evidence folder from the specified assessment report in Audit Manager.

Returns the registration status of an account in Audit Manager.

Returns an assessment from Audit Manager.

Returns a framework from Audit Manager.

Returns the URL of an assessment report in Audit Manager.

Returns a control from Audit Manager.

Returns a list of delegations from an audit owner to a delegate.

Returns an evidence folder from the specified assessment in Audit Manager.

Returns the evidence folders from a specified assessment in Audit Manager.

Returns a list of evidence folders that are associated with a specified control in an Audit Manager assessment.

Gets the latest analytics data for all your current active assessments.

Gets the latest analytics data for a specific active assessment.

Returns the name of the delegated Amazon Web Services administrator account for the organization.

Returns a list of all of the Amazon Web Services that you can choose to include in your assessment.

Returns the settings for the specified Amazon Web Services account.

Lists the latest analytics data for controls within a specific control domain and a specific active assessment.

Returns a list of sent or received share requests for custom frameworks in Audit Manager.

Returns a list of the frameworks that are available in the Audit Manager framework library.

Returns a list of assessment reports created in Audit Manager.

Returns a list of current and past assessments from Audit Manager.

Lists the latest analytics data for control domains across all of your active assessments.

Lists analytics data for control domains within a specified active assessment.

Lists the latest analytics data for controls within a specific control domain across all active assessments.

Returns a list of keywords that are pre-mapped to the specified control data source.

Returns a list of tags for the specified resource in Audit Manager.

Enables Audit Manager for the specified Amazon Web Services account.

Enables an Amazon Web Services account within the organization as the delegated administrator for Audit Manager.

Creates a share request for a custom framework in Audit Manager.

Tags the specified resource in Audit Manager.

Removes a tag from a resource in Audit Manager.

Updates the status of a control set in an Audit Manager assessment.

Updates a share request for a custom framework in Audit Manager.

Updates the status of an assessment in Audit Manager.

Updates a custom control in Audit Manager.

Updates Audit Manager settings for the current account.

Validates the integrity of an assessment report in Audit Manager.

Link to this section Functions

Link to this function

associate_assessment_report_evidence_folder(client, assessment_id, input, options \\ [])

View Source

Associates an evidence folder to an assessment report in an Audit Manager assessment.

Link to this function

batch_associate_assessment_report_evidence(client, assessment_id, input, options \\ [])

View Source

Associates a list of evidence to an assessment report in an Audit Manager assessment.

Link to this function

batch_create_delegation_by_assessment(client, assessment_id, input, options \\ [])

View Source

Creates a batch of delegations for an assessment in Audit Manager.

Link to this function

batch_delete_delegation_by_assessment(client, assessment_id, input, options \\ [])

View Source

Deletes a batch of delegations for an assessment in Audit Manager.

Link to this function

batch_disassociate_assessment_report_evidence(client, assessment_id, input, options \\ [])

View Source

Disassociates a list of evidence from an assessment report in Audit Manager.

Link to this function

batch_import_evidence_to_assessment_control(client, assessment_id, control_id, control_set_id, input, options \\ [])

View Source

Uploads one or more pieces of evidence to a control in an Audit Manager assessment.

You can upload manual evidence from any Amazon Simple Storage Service (Amazon S3) bucket by specifying the S3 URI of the evidence.

You must upload manual evidence to your S3 bucket before you can upload it to your assessment. For instructions, see CreateBucket and PutObject in the Amazon Simple Storage Service API Reference.

The following restrictions apply to this action:

  • Maximum size of an individual evidence file: 100 MB

  • Number of daily manual evidence uploads per control: 100

  • Supported file formats: See Supported file types for manual evidence in the Audit Manager User Guide

For more information about Audit Manager service restrictions, see Quotas and restrictions for Audit Manager.

Link to this function

create_assessment(client, input, options \\ [])

View Source

Creates an assessment in Audit Manager.

Link to this function

create_assessment_framework(client, input, options \\ [])

View Source

Creates a custom framework in Audit Manager.

Link to this function

create_assessment_report(client, assessment_id, input, options \\ [])

View Source

Creates an assessment report for the specified assessment.

Link to this function

create_control(client, input, options \\ [])

View Source

Creates a new custom control in Audit Manager.

Link to this function

delete_assessment(client, assessment_id, input, options \\ [])

View Source

Deletes an assessment in Audit Manager.

Link to this function

delete_assessment_framework(client, framework_id, input, options \\ [])

View Source

Deletes a custom framework in Audit Manager.

Link to this function

delete_assessment_framework_share(client, request_id, input, options \\ [])

View Source

Deletes a share request for a custom framework in Audit Manager.

Link to this function

delete_assessment_report(client, assessment_id, assessment_report_id, input, options \\ [])

View Source

Deletes an assessment report in Audit Manager.

When you run the DeleteAssessmentReport operation, Audit Manager attempts to delete the following data:

  1. The specified assessment report that’s stored in your S3 bucket

  2. The associated metadata that’s stored in Audit Manager

If Audit Manager can’t access the assessment report in your S3 bucket, the report isn’t deleted. In this event, the DeleteAssessmentReport operation doesn’t fail. Instead, it proceeds to delete the associated metadata only. You must then delete the assessment report from the S3 bucket yourself.

This scenario happens when Audit Manager receives a 403 (Forbidden) or 404 (Not Found) error from Amazon S3. To avoid this, make sure that your S3 bucket is available, and that you configured the correct permissions for Audit Manager to delete resources in your S3 bucket. For an example permissions policy that you can use, see Assessment report destination permissions in the Audit Manager User Guide. For information about the issues that could cause a 403 (Forbidden) or 404 (Not Found) error from Amazon S3, see List of Error Codes in the Amazon Simple Storage Service API Reference.

Link to this function

delete_control(client, control_id, input, options \\ [])

View Source

Deletes a custom control in Audit Manager.

Link to this function

deregister_account(client, input, options \\ [])

View Source

Deregisters an account in Audit Manager.

Before you deregister, you can use the UpdateSettings API operation to set your preferred data retention policy. By default, Audit Manager retains your data. If you want to delete your data, you can use the DeregistrationPolicy attribute to request the deletion of your data.

For more information about data retention, see Data Protection in the Audit Manager User Guide.

Link to this function

deregister_organization_admin_account(client, input, options \\ [])

View Source

Removes the specified Amazon Web Services account as a delegated administrator for Audit Manager.

When you remove a delegated administrator from your Audit Manager settings, you continue to have access to the evidence that you previously collected under that account. This is also the case when you deregister a delegated administrator from Organizations. However, Audit Manager stops collecting and attaching evidence to that delegated administrator account moving forward.

Keep in mind the following cleanup task if you use evidence finder:

Before you use your management account to remove a delegated administrator, make sure that the current delegated administrator account signs in to Audit Manager and disables evidence finder first. Disabling evidence finder automatically deletes the event data store that was created in their account when they enabled evidence finder. If this task isn’t completed, the event data store remains in their account. In this case, we recommend that the original delegated administrator goes to CloudTrail Lake and manually deletes the event data store.

This cleanup task is necessary to ensure that you don't end up with multiple event data stores. Audit Manager ignores an unused event data store after you remove or change a delegated administrator account. However, the unused event data store continues to incur storage costs from CloudTrail Lake if you don't delete it.

When you deregister a delegated administrator account for Audit Manager, the data for that account isn’t deleted. If you want to delete resource data for a delegated administrator account, you must perform that task separately before you deregister the account. Either, you can do this in the Audit Manager console. Or, you can use one of the delete API operations that are provided by Audit Manager.

To delete your Audit Manager resource data, see the following instructions:

DeleteAssessment (see also: Deleting an assessment in the Audit Manager User Guide*)

DeleteAssessmentFramework (see also: Deleting a custom framework in the Audit Manager User Guide*)

DeleteAssessmentFrameworkShare (see also: Deleting a share request in the Audit Manager User Guide*)

DeleteAssessmentReport (see also: Deleting an assessment report in the Audit Manager User Guide*)

DeleteControl (see also: Deleting a custom control in the Audit Manager User Guide*)

At this time, Audit Manager doesn't provide an option to delete evidence for a specific delegated administrator. Instead, when your management account deregisters Audit Manager, we perform a cleanup for the current delegated administrator account at the time of deregistration.

Link to this function

disassociate_assessment_report_evidence_folder(client, assessment_id, input, options \\ [])

View Source

Disassociates an evidence folder from the specified assessment report in Audit Manager.

Link to this function

get_account_status(client, options \\ [])

View Source

Returns the registration status of an account in Audit Manager.

Link to this function

get_assessment(client, assessment_id, options \\ [])

View Source

Returns an assessment from Audit Manager.

Link to this function

get_assessment_framework(client, framework_id, options \\ [])

View Source

Returns a framework from Audit Manager.

Link to this function

get_assessment_report_url(client, assessment_id, assessment_report_id, options \\ [])

View Source

Returns the URL of an assessment report in Audit Manager.

Link to this function

get_change_logs(client, assessment_id, control_id \\ nil, control_set_id \\ nil, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Returns a list of changelogs from Audit Manager.

Link to this function

get_control(client, control_id, options \\ [])

View Source

Returns a control from Audit Manager.

Link to this function

get_delegations(client, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Returns a list of delegations from an audit owner to a delegate.

Link to this function

get_evidence(client, assessment_id, control_set_id, evidence_folder_id, evidence_id, options \\ [])

View Source

Returns evidence from Audit Manager.

Link to this function

get_evidence_by_evidence_folder(client, assessment_id, control_set_id, evidence_folder_id, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Returns all evidence from a specified evidence folder in Audit Manager.

Link to this function

get_evidence_folder(client, assessment_id, control_set_id, evidence_folder_id, options \\ [])

View Source

Returns an evidence folder from the specified assessment in Audit Manager.

Link to this function

get_evidence_folders_by_assessment(client, assessment_id, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Returns the evidence folders from a specified assessment in Audit Manager.

Link to this function

get_evidence_folders_by_assessment_control(client, assessment_id, control_id, control_set_id, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Returns a list of evidence folders that are associated with a specified control in an Audit Manager assessment.

Link to this function

get_insights(client, options \\ [])

View Source

Gets the latest analytics data for all your current active assessments.

Link to this function

get_insights_by_assessment(client, assessment_id, options \\ [])

View Source

Gets the latest analytics data for a specific active assessment.

Link to this function

get_organization_admin_account(client, options \\ [])

View Source

Returns the name of the delegated Amazon Web Services administrator account for the organization.

Link to this function

get_services_in_scope(client, options \\ [])

View Source

Returns a list of all of the Amazon Web Services that you can choose to include in your assessment.

When you create an assessment, specify which of these services you want to include to narrow the assessment's scope.

Link to this function

get_settings(client, attribute, options \\ [])

View Source

Returns the settings for the specified Amazon Web Services account.

Link to this function

list_assessment_control_insights_by_control_domain(client, assessment_id, control_domain_id, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Lists the latest analytics data for controls within a specific control domain and a specific active assessment.

Control insights are listed only if the control belongs to the control domain and assessment that was specified. Moreover, the control must have collected evidence on the lastUpdated date of controlInsightsByAssessment. If neither of these conditions are met, no data is listed for that control.

Link to this function

list_assessment_framework_share_requests(client, max_results \\ nil, next_token \\ nil, request_type, options \\ [])

View Source

Returns a list of sent or received share requests for custom frameworks in Audit Manager.

Link to this function

list_assessment_frameworks(client, framework_type, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Returns a list of the frameworks that are available in the Audit Manager framework library.

Link to this function

list_assessment_reports(client, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Returns a list of assessment reports created in Audit Manager.

Link to this function

list_assessments(client, max_results \\ nil, next_token \\ nil, status \\ nil, options \\ [])

View Source

Returns a list of current and past assessments from Audit Manager.

Link to this function

list_control_domain_insights(client, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Lists the latest analytics data for control domains across all of your active assessments.

A control domain is listed only if at least one of the controls within that domain collected evidence on the lastUpdated date of controlDomainInsights. If this condition isn’t met, no data is listed for that control domain.

Link to this function

list_control_domain_insights_by_assessment(client, assessment_id, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Lists analytics data for control domains within a specified active assessment.

A control domain is listed only if at least one of the controls within that domain collected evidence on the lastUpdated date of controlDomainInsights. If this condition isn’t met, no data is listed for that domain.

Link to this function

list_control_insights_by_control_domain(client, control_domain_id, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Lists the latest analytics data for controls within a specific control domain across all active assessments.

Control insights are listed only if the control belongs to the control domain that was specified and the control collected evidence on the lastUpdated date of controlInsightsMetadata. If neither of these conditions are met, no data is listed for that control.

Link to this function

list_controls(client, control_type, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Returns a list of controls from Audit Manager.

Link to this function

list_keywords_for_data_source(client, max_results \\ nil, next_token \\ nil, source, options \\ [])

View Source

Returns a list of keywords that are pre-mapped to the specified control data source.

Link to this function

list_notifications(client, max_results \\ nil, next_token \\ nil, options \\ [])

View Source

Returns a list of all Audit Manager notifications.

Link to this function

list_tags_for_resource(client, resource_arn, options \\ [])

View Source

Returns a list of tags for the specified resource in Audit Manager.

Link to this function

register_account(client, input, options \\ [])

View Source

Enables Audit Manager for the specified Amazon Web Services account.

Link to this function

register_organization_admin_account(client, input, options \\ [])

View Source

Enables an Amazon Web Services account within the organization as the delegated administrator for Audit Manager.

Link to this function

start_assessment_framework_share(client, framework_id, input, options \\ [])

View Source

Creates a share request for a custom framework in Audit Manager.

The share request specifies a recipient and notifies them that a custom framework is available. Recipients have 120 days to accept or decline the request. If no action is taken, the share request expires.

When you create a share request, Audit Manager stores a snapshot of your custom framework in the US East (N. Virginia) Amazon Web Services Region. Audit Manager also stores a backup of the same snapshot in the US West (Oregon) Amazon Web Services Region.

Audit Manager deletes the snapshot and the backup snapshot when one of the following events occurs:

  • The sender revokes the share request.

  • The recipient declines the share request.

  • The recipient encounters an error and doesn't successfully accept the share request.

  • The share request expires before the recipient responds to the request.

When a sender resends a share request, the snapshot is replaced with an updated version that corresponds with the latest version of the custom framework.

When a recipient accepts a share request, the snapshot is replicated into their Amazon Web Services account under the Amazon Web Services Region that was specified in the share request.

When you invoke the StartAssessmentFrameworkShare API, you are about to share a custom framework with another Amazon Web Services account. You may not share a custom framework that is derived from a standard framework if the standard framework is designated as not eligible for sharing by Amazon Web Services, unless you have obtained permission to do so from the owner of the standard framework. To learn more about which standard frameworks are eligible for sharing, see Framework sharing eligibility in the Audit Manager User Guide.

Link to this function

tag_resource(client, resource_arn, input, options \\ [])

View Source

Tags the specified resource in Audit Manager.

Link to this function

untag_resource(client, resource_arn, input, options \\ [])

View Source

Removes a tag from a resource in Audit Manager.

Link to this function

update_assessment(client, assessment_id, input, options \\ [])

View Source

Edits an Audit Manager assessment.

Link to this function

update_assessment_control(client, assessment_id, control_id, control_set_id, input, options \\ [])

View Source

Updates a control within an assessment in Audit Manager.

Link to this function

update_assessment_control_set_status(client, assessment_id, control_set_id, input, options \\ [])

View Source

Updates the status of a control set in an Audit Manager assessment.

Link to this function

update_assessment_framework(client, framework_id, input, options \\ [])

View Source

Updates a custom framework in Audit Manager.

Link to this function

update_assessment_framework_share(client, request_id, input, options \\ [])

View Source

Updates a share request for a custom framework in Audit Manager.

Link to this function

update_assessment_status(client, assessment_id, input, options \\ [])

View Source

Updates the status of an assessment in Audit Manager.

Link to this function

update_control(client, control_id, input, options \\ [])

View Source

Updates a custom control in Audit Manager.

Link to this function

update_settings(client, input, options \\ [])

View Source

Updates Audit Manager settings for the current account.

Link to this function

validate_assessment_report_integrity(client, input, options \\ [])

View Source

Validates the integrity of an assessment report in Audit Manager.