assessments_metadata
Creates, updates, deletes, gets or lists an assessments_metadata resource.
Overview
| Name | assessments_metadata |
| Type | Resource |
| Id | azure.security.assessments_metadata |
Fields
The following fields are returned by SELECT queries:
- get_in_subscription
- get
- list_by_subscription
- list
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assessmentType | string | BuiltIn if the assessment based on built-in Azure Policy definition, Custom if the assessment based on custom Azure Policy definition. Required. Known values are: "Unknown", "BuiltIn", "Custom", "CustomPolicy", "CustomerManaged", "BuiltInPolicy", "VerifiedPartner", "ManualBuiltInPolicy", "ManualBuiltIn", "ManualCustomPolicy", and "DynamicBuiltIn". (Unknown, BuiltIn, Custom, CustomPolicy, CustomerManaged, BuiltInPolicy, VerifiedPartner, ManualBuiltInPolicy, ManualBuiltIn, ManualCustomPolicy, DynamicBuiltIn) |
categories | array | :vartype categories: list[str or ~azure.mgmt.security.models.Categories] |
description | string | Human readable description of the assessment. |
displayName | string | User friendly display name of the assessment. Required. |
implementationEffort | string | The implementation effort required to remediate this assessment. Known values are: "Low", "Moderate", and "High". (Low, Moderate, High) |
partnerData | object | Describes the partner that created the assessment. |
plannedDeprecationDate | string | :vartype planned_deprecation_date: str |
policyDefinitionId | string | Azure resource ID of the policy definition that turns this assessment calculation on. |
preview | boolean | True if this assessment is in preview release status. |
publishDates | object | :vartype publish_dates: ~azure.mgmt.security.models.SecurityAssessmentMetadataPropertiesResponsePublishDates |
remediationDescription | string | Human readable description of what you should do to mitigate this security issue. |
severity | string | The severity level of the assessment. Required. Known values are: "Low", "Medium", "High", and "Critical". (Low, Medium, High, Critical) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tactics | array | :vartype tactics: list[str or ~azure.mgmt.security.models.Tactics] |
techniques | array | :vartype techniques: list[str or ~azure.mgmt.security.models.Techniques] |
threats | array | :vartype threats: list[str or ~azure.mgmt.security.models.Threats] |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
userImpact | string | The user impact of the assessment. Known values are: "Low", "Moderate", and "High". (Low, Moderate, High) |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assessmentType | string | BuiltIn if the assessment based on built-in Azure Policy definition, Custom if the assessment based on custom Azure Policy definition. Required. Known values are: "Unknown", "BuiltIn", "Custom", "CustomPolicy", "CustomerManaged", "BuiltInPolicy", "VerifiedPartner", "ManualBuiltInPolicy", "ManualBuiltIn", "ManualCustomPolicy", and "DynamicBuiltIn". (Unknown, BuiltIn, Custom, CustomPolicy, CustomerManaged, BuiltInPolicy, VerifiedPartner, ManualBuiltInPolicy, ManualBuiltIn, ManualCustomPolicy, DynamicBuiltIn) |
categories | array | :vartype categories: list[str or ~azure.mgmt.security.models.Categories] |
description | string | Human readable description of the assessment. |
displayName | string | User friendly display name of the assessment. Required. |
implementationEffort | string | The implementation effort required to remediate this assessment. Known values are: "Low", "Moderate", and "High". (Low, Moderate, High) |
partnerData | object | Describes the partner that created the assessment. |
plannedDeprecationDate | string | :vartype planned_deprecation_date: str |
policyDefinitionId | string | Azure resource ID of the policy definition that turns this assessment calculation on. |
preview | boolean | True if this assessment is in preview release status. |
publishDates | object | :vartype publish_dates: ~azure.mgmt.security.models.SecurityAssessmentMetadataPropertiesResponsePublishDates |
remediationDescription | string | Human readable description of what you should do to mitigate this security issue. |
severity | string | The severity level of the assessment. Required. Known values are: "Low", "Medium", "High", and "Critical". (Low, Medium, High, Critical) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tactics | array | :vartype tactics: list[str or ~azure.mgmt.security.models.Tactics] |
techniques | array | :vartype techniques: list[str or ~azure.mgmt.security.models.Techniques] |
threats | array | :vartype threats: list[str or ~azure.mgmt.security.models.Threats] |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
userImpact | string | The user impact of the assessment. Known values are: "Low", "Moderate", and "High". (Low, Moderate, High) |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assessmentType | string | BuiltIn if the assessment based on built-in Azure Policy definition, Custom if the assessment based on custom Azure Policy definition. Required. Known values are: "Unknown", "BuiltIn", "Custom", "CustomPolicy", "CustomerManaged", "BuiltInPolicy", "VerifiedPartner", "ManualBuiltInPolicy", "ManualBuiltIn", "ManualCustomPolicy", and "DynamicBuiltIn". (Unknown, BuiltIn, Custom, CustomPolicy, CustomerManaged, BuiltInPolicy, VerifiedPartner, ManualBuiltInPolicy, ManualBuiltIn, ManualCustomPolicy, DynamicBuiltIn) |
categories | array | :vartype categories: list[str or ~azure.mgmt.security.models.Categories] |
description | string | Human readable description of the assessment. |
displayName | string | User friendly display name of the assessment. Required. |
implementationEffort | string | The implementation effort required to remediate this assessment. Known values are: "Low", "Moderate", and "High". (Low, Moderate, High) |
partnerData | object | Describes the partner that created the assessment. |
plannedDeprecationDate | string | :vartype planned_deprecation_date: str |
policyDefinitionId | string | Azure resource ID of the policy definition that turns this assessment calculation on. |
preview | boolean | True if this assessment is in preview release status. |
publishDates | object | :vartype publish_dates: ~azure.mgmt.security.models.SecurityAssessmentMetadataPropertiesResponsePublishDates |
remediationDescription | string | Human readable description of what you should do to mitigate this security issue. |
severity | string | The severity level of the assessment. Required. Known values are: "Low", "Medium", "High", and "Critical". (Low, Medium, High, Critical) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tactics | array | :vartype tactics: list[str or ~azure.mgmt.security.models.Tactics] |
techniques | array | :vartype techniques: list[str or ~azure.mgmt.security.models.Techniques] |
threats | array | :vartype threats: list[str or ~azure.mgmt.security.models.Threats] |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
userImpact | string | The user impact of the assessment. Known values are: "Low", "Moderate", and "High". (Low, Moderate, High) |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assessmentType | string | BuiltIn if the assessment based on built-in Azure Policy definition, Custom if the assessment based on custom Azure Policy definition. Required. Known values are: "Unknown", "BuiltIn", "Custom", "CustomPolicy", "CustomerManaged", "BuiltInPolicy", "VerifiedPartner", "ManualBuiltInPolicy", "ManualBuiltIn", "ManualCustomPolicy", and "DynamicBuiltIn". (Unknown, BuiltIn, Custom, CustomPolicy, CustomerManaged, BuiltInPolicy, VerifiedPartner, ManualBuiltInPolicy, ManualBuiltIn, ManualCustomPolicy, DynamicBuiltIn) |
categories | array | :vartype categories: list[str or ~azure.mgmt.security.models.Categories] |
description | string | Human readable description of the assessment. |
displayName | string | User friendly display name of the assessment. Required. |
implementationEffort | string | The implementation effort required to remediate this assessment. Known values are: "Low", "Moderate", and "High". (Low, Moderate, High) |
partnerData | object | Describes the partner that created the assessment. |
plannedDeprecationDate | string | :vartype planned_deprecation_date: str |
policyDefinitionId | string | Azure resource ID of the policy definition that turns this assessment calculation on. |
preview | boolean | True if this assessment is in preview release status. |
publishDates | object | :vartype publish_dates: ~azure.mgmt.security.models.SecurityAssessmentMetadataPropertiesResponsePublishDates |
remediationDescription | string | Human readable description of what you should do to mitigate this security issue. |
severity | string | The severity level of the assessment. Required. Known values are: "Low", "Medium", "High", and "Critical". (Low, Medium, High, Critical) |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tactics | array | :vartype tactics: list[str or ~azure.mgmt.security.models.Tactics] |
techniques | array | :vartype techniques: list[str or ~azure.mgmt.security.models.Techniques] |
threats | array | :vartype threats: list[str or ~azure.mgmt.security.models.Threats] |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
userImpact | string | The user impact of the assessment. Known values are: "Low", "Moderate", and "High". (Low, Moderate, High) |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get_in_subscription | select | assessment_metadata_name, subscription_id | Get metadata information on an assessment type in a specific subscription. | |
get | select | assessment_metadata_name | Get metadata information on an assessment type. | |
list_by_subscription | select | subscription_id | Get metadata information on all assessment types in a specific subscription. | |
list | select | Get metadata information on all assessment types. | ||
create_in_subscription | insert | assessment_metadata_name, subscription_id | Create metadata information on an assessment type in a specific subscription. | |
delete_in_subscription | delete | assessment_metadata_name, subscription_id | Delete metadata information on an assessment type in a specific subscription, will cause the deletion of all the assessments of that type in that subscription. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
assessment_metadata_name | string | The Assessment Key - Unique key for the assessment type. Required. |
subscription_id | string |
SELECT examples
- get_in_subscription
- get
- list_by_subscription
- list
Get metadata information on an assessment type in a specific subscription.
SELECT
id,
name,
assessmentType,
categories,
description,
displayName,
implementationEffort,
partnerData,
plannedDeprecationDate,
policyDefinitionId,
preview,
publishDates,
remediationDescription,
severity,
systemData,
tactics,
techniques,
threats,
type,
userImpact
FROM azure.security.assessments_metadata
WHERE assessment_metadata_name = '{{ assessment_metadata_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Get metadata information on an assessment type.
SELECT
id,
name,
assessmentType,
categories,
description,
displayName,
implementationEffort,
partnerData,
plannedDeprecationDate,
policyDefinitionId,
preview,
publishDates,
remediationDescription,
severity,
systemData,
tactics,
techniques,
threats,
type,
userImpact
FROM azure.security.assessments_metadata
WHERE assessment_metadata_name = '{{ assessment_metadata_name }}' -- required
;
Get metadata information on all assessment types in a specific subscription.
SELECT
id,
name,
assessmentType,
categories,
description,
displayName,
implementationEffort,
partnerData,
plannedDeprecationDate,
policyDefinitionId,
preview,
publishDates,
remediationDescription,
severity,
systemData,
tactics,
techniques,
threats,
type,
userImpact
FROM azure.security.assessments_metadata
WHERE subscription_id = '{{ subscription_id }}' -- required
;
Get metadata information on all assessment types.
SELECT
id,
name,
assessmentType,
categories,
description,
displayName,
implementationEffort,
partnerData,
plannedDeprecationDate,
policyDefinitionId,
preview,
publishDates,
remediationDescription,
severity,
systemData,
tactics,
techniques,
threats,
type,
userImpact
FROM azure.security.assessments_metadata
;
INSERT examples
- create_in_subscription
- Manifest
Create metadata information on an assessment type in a specific subscription.
INSERT INTO azure.security.assessments_metadata (
properties,
assessment_metadata_name,
subscription_id
)
SELECT
'{{ properties }}',
'{{ assessment_metadata_name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
properties,
systemData,
type
;
# Description fields are for documentation purposes
- name: assessments_metadata
props:
- name: assessment_metadata_name
value: "{{ assessment_metadata_name }}"
description: Required parameter for the assessments_metadata resource.
- name: subscription_id
value: "{{ subscription_id }}"
description: Required parameter for the assessments_metadata resource.
- name: properties
description: |
Describes properties of an assessment metadata response.
value:
displayName: "{{ displayName }}"
policyDefinitionId: "{{ policyDefinitionId }}"
description: "{{ description }}"
remediationDescription: "{{ remediationDescription }}"
categories:
- "{{ categories }}"
severity: "{{ severity }}"
userImpact: "{{ userImpact }}"
implementationEffort: "{{ implementationEffort }}"
threats:
- "{{ threats }}"
preview: {{ preview }}
assessmentType: "{{ assessmentType }}"
partnerData:
partnerName: "{{ partnerName }}"
productName: "{{ productName }}"
secret: "{{ secret }}"
publishDates:
GA: "{{ GA }}"
public: "{{ public }}"
plannedDeprecationDate: "{{ plannedDeprecationDate }}"
tactics:
- "{{ tactics }}"
techniques:
- "{{ techniques }}"
DELETE examples
- delete_in_subscription
Delete metadata information on an assessment type in a specific subscription, will cause the deletion of all the assessments of that type in that subscription.
DELETE FROM azure.security.assessments_metadata
WHERE assessment_metadata_name = '{{ assessment_metadata_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;