Skip to content


securityhub R Documentation

AWS SecurityHub


Security Hub provides you with a comprehensive view of your security state in Amazon Web Services and helps you assess your Amazon Web Services environment against security industry standards and best practices.

Security Hub collects security data across Amazon Web Services accounts, Amazon Web Services services, and supported third-party products and helps you analyze your security trends and identify the highest priority security issues.

To help you manage the security state of your organization, Security Hub supports multiple security standards. These include the Amazon Web Services Foundational Security Best Practices (FSBP) standard developed by Amazon Web Services, and external compliance frameworks such as the Center for Internet Security (CIS), the Payment Card Industry Data Security Standard (PCI DSS), and the National Institute of Standards and Technology (NIST). Each standard includes several security controls, each of which represents a security best practice. Security Hub runs checks against security controls and generates control findings to help you assess your compliance against security best practices.

In addition to generating control findings, Security Hub also receives findings from other Amazon Web Services services, such as Amazon GuardDuty and Amazon Inspector, and supported third-party products. This gives you a single pane of glass into a variety of security-related issues. You can also send Security Hub findings to other Amazon Web Services services and supported third-party products.

Security Hub offers automation features that help you triage and remediate security issues. For example, you can use automation rules to automatically update critical findings when a security check fails. You can also leverage the integration with Amazon EventBridge to trigger automatic responses to specific findings.

This guide, the Security Hub API Reference, provides information about the Security Hub API. This includes supported resources, HTTP methods, parameters, and schemas. If you're new to Security Hub, you might find it helpful to also review the Security Hub User Guide . The user guide explains key concepts and provides procedures that demonstrate how to use Security Hub features. It also provides information about topics such as integrating Security Hub with other Amazon Web Services services.

In addition to interacting with Security Hub by making calls to the Security Hub API, you can use a current version of an Amazon Web Services command line tool or SDK. Amazon Web Services provides tools and SDKs that consist of libraries and sample code for various languages and platforms, such as PowerShell, Java, Go, Python, C++, and .NET. These tools and SDKs provide convenient, programmatic access to Security Hub and other Amazon Web Services services . They also handle tasks such as signing requests, managing errors, and retrying requests automatically. For information about installing and using the Amazon Web Services tools and SDKs, see Tools to Build on Amazon Web Services.

With the exception of operations that are related to central configuration, Security Hub API requests are executed only in the Amazon Web Services Region that is currently active or in the specific Amazon Web Services Region that you specify in your request. Any configuration or settings change that results from the operation is applied only to that Region. To make the same change in other Regions, call the same API operation in each Region in which you want to apply the change. When you use central configuration, API requests for enabling Security Hub, standards, and controls are executed in the home Region and all linked Regions. For a list of central configuration operations, see the Central configuration terms and concepts section of the Security Hub User Guide.

The following throttling limits apply to Security Hub API operations.

  • batch_enable_standards - RateLimit of 1 request per second. BurstLimit of 1 request per second.

  • get_findings - RateLimit of 3 requests per second. BurstLimit of 6 requests per second.

  • batch_import_findings - RateLimit of 10 requests per second. BurstLimit of 30 requests per second.

  • batch_update_findings - RateLimit of 10 requests per second. BurstLimit of 30 requests per second.

  • update_standards_control - RateLimit of 1 request per second. BurstLimit of 5 requests per second.

  • All other operations - RateLimit of 10 requests per second. BurstLimit of 30 requests per second.


  config = list(),
  credentials = list(),
  endpoint = NULL,
  region = NULL



Optional configuration of credentials, endpoint, and/or region.

  • credentials:

    • creds:

      • access_key_id: AWS access key ID

      • secret_access_key: AWS secret access key

      • session_token: AWS temporary session token

    • profile: The name of a profile to use. If not given, then the default profile is used.

    • anonymous: Set anonymous credentials.

  • endpoint: The complete URL to use for the constructed client.

  • region: The AWS Region used in instantiating the client.

  • close_connection: Immediately close all HTTP connections.

  • timeout: The time in seconds till a timeout exception is thrown when attempting to make a connection. The default is 60 seconds.

  • s3_force_path_style: Set this to true to force the request to use path-style addressing, i.e. ⁠⁠.

  • sts_regional_endpoint: Set sts regional endpoint resolver to regional or legacy


Optional credentials shorthand for the config parameter

  • creds:

    • access_key_id: AWS access key ID

    • secret_access_key: AWS secret access key

    • session_token: AWS temporary session token

  • profile: The name of a profile to use. If not given, then the default profile is used.

  • anonymous: Set anonymous credentials.


Optional shorthand for complete URL to use for the constructed client.


Optional shorthand for AWS Region used in instantiating the client.


A client for the service. You can call the service's operations using syntax like svc$operation(...), where svc is the name you've assigned to the client. The available operations are listed in the Operations section.

Service syntax

svc <- securityhub(
  config = list(
    credentials = list(
      creds = list(
        access_key_id = "string",
        secret_access_key = "string",
        session_token = "string"
      profile = "string",
      anonymous = "logical"
    endpoint = "string",
    region = "string",
    close_connection = "logical",
    timeout = "numeric",
    s3_force_path_style = "logical",
    sts_regional_endpoint = "string"
  credentials = list(
    creds = list(
      access_key_id = "string",
      secret_access_key = "string",
      session_token = "string"
    profile = "string",
    anonymous = "logical"
  endpoint = "string",
  region = "string"


We recommend using Organizations instead of Security Hub invitations to manage your member accounts
This method is deprecated
Deletes one or more automation rules
Disables the standards specified by the provided StandardsSubscriptionArns
Enables the standards specified by the provided StandardsArn
Retrieves a list of details for automation rules based on rule Amazon Resource Names (ARNs)
Returns associations between an Security Hub configuration and a batch of target accounts, organizational units, or the root
Provides details about a batch of security controls for the current Amazon Web Services account and Amazon Web Services Region
For a batch of security controls and standards, identifies whether each control is currently enabled or disabled in a standard
Imports security findings generated by a finding provider into Security Hub
Updates one or more automation rules based on rule Amazon Resource Names (ARNs) and input parameters
Used by Security Hub customers to update information about their investigation into a finding
For a batch of security controls and standards, this operation updates the enablement status of a control in a standard
Creates a custom action target in Security Hub
Creates an automation rule based on input parameters
Creates a configuration policy with the defined configuration
The aggregation Region is now called the home Region
Creates a custom insight in Security Hub
Creates a member association in Security Hub between the specified accounts and the account used to make the request, which is the administrator account
We recommend using Organizations instead of Security Hub invitations to manage your member accounts
Deletes a custom action target from Security Hub
Deletes a configuration policy
The aggregation Region is now called the home Region
Deletes the insight specified by the InsightArn
We recommend using Organizations instead of Security Hub invitations to manage your member accounts
Deletes the specified member accounts from Security Hub
Returns a list of the custom action targets in Security Hub in your account
Returns details about the Hub resource in your account, including the HubArn and the time when you enabled Security Hub
Returns information about the way your organization is configured in Security Hub
Returns information about product integrations in Security Hub
Returns a list of the available standards in Security Hub
Returns a list of security standards controls
Disables the integration of the specified product with Security Hub
Disables a Security Hub administrator account
Disables Security Hub in your account only in the current Amazon Web Services Region
Disassociates the current Security Hub member account from the associated administrator account
This method is deprecated
Disassociates the specified member accounts from the associated administrator account
Enables the integration of a partner product with Security Hub
Designates the Security Hub administrator account for an organization
Enables Security Hub for your account in the current Region or the Region you specify in the request
Provides the details for the Security Hub administrator account for the current member account
Provides information about a configuration policy
Returns the association between a configuration and a target account, organizational unit, or the root
Returns a list of the standards that are currently enabled
The aggregation Region is now called the home Region
Returns history for a Security Hub finding in the last 90 days
Returns a list of findings that match the specified criteria
Lists the results of the Security Hub insight specified by the insight ARN
Lists and describes insights for the specified insight ARNs
We recommend using Organizations instead of Security Hub invitations to manage your member accounts
This method is deprecated
Returns the details for the Security Hub member accounts for the specified account IDs
Retrieves the definition of a security control
We recommend using Organizations instead of Security Hub invitations to manage your member accounts
A list of automation rules and their metadata for the calling account
Lists the configuration policies that the Security Hub delegated administrator has created for your organization
Provides information about the associations for your configuration policies and self-managed behavior
Lists all findings-generating solutions (products) that you are subscribed to receive findings from in Security Hub
If cross-Region aggregation is enabled, then ListFindingAggregators returns the Amazon Resource Name (ARN) of the finding aggregator
We recommend using Organizations instead of Security Hub invitations to manage your member accounts
Lists details about all member accounts for the current Security Hub administrator account
Lists the Security Hub administrator accounts
Lists all of the security controls that apply to a specified standard
Specifies whether a control is currently enabled or disabled in each enabled standard in the calling account
Returns a list of tags associated with a resource
Associates a target account, organizational unit, or the root with a specified configuration
Disassociates a target account, organizational unit, or the root from a specified configuration
Adds one or more tags to a resource
Removes one or more tags from a resource
Updates the name and description of a custom action target in Security Hub
Updates a configuration policy
The aggregation Region is now called the home Region
UpdateFindings is a deprecated operation
Updates the Security Hub insight identified by the specified insight ARN
Updates the configuration of your organization in Security Hub
Updates the properties of a security control
Updates configuration options for Security Hub
Used to control whether an individual security standard control is enabled or disabled


## Not run: 
svc <- securityhub()
  Foo = 123

## End(Not run)