{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "lowerPlaneReadOnlyAccess",
"Effect": "Allow",
"Action": [
"access-analyzer:Get*",
"access-analyzer:List*",
"account:Get*",
"account:List*",
"acm:Describe*",
"acm:Get*",
"acm:List*",
"application-autoscaling:Describe*",
"autoscaling:Describe*",
"cloudtrail:Describe*",
"cloudtrail:Get*",
"cloudtrail:List*",
"cloudwatch:Describe*",
"cloudwatch:Get*",
"cloudwatch:List*",
"logs:Describe*",
"logs:Get*",
"logs:List*",
"codecommit:BatchGet*",
"codecommit:Get*",
"codecommit:GitPull",
"codecommit:List*",
"config:BatchGet*",
"config:Describe*",
"config:Get*",
"config:List*",
"docdb:Describe*",
"docdb:ListTagsForResource",
"dynamodb:Describe*",
"dynamodb:List*",
"ec2:Describe*",
"ec2:Get*",
"ecr:BatchGet*",
"ecr:Describe*",
"ecr:Get*",
"ecr:List*",
"ecs:Describe*",
"ecs:List*",
"efs:Describe*",
"eks:Describe*",
"eks:List*",
"elasticloadbalancing:Describe*",
"guardduty:Get*",
"guardduty:List*",
"iam:GenerateCredentialReport",
"iam:Get*",
"iam:List*",
"identitystore:Describe*",
"identitystore:Get*",
"identitystore:List*",
"inspector2:BatchGet*",
"inspector2:Get*",
"inspector2:List*",
"kms:Describe*",
"kms:Get*",
"kms:List*",
"lambda:Get*",
"lambda:List*",
"organizations:Describe*",
"organizations:List*",
"rds:Describe*",
"rds:ListTagsForResource",
"redshift:Describe*",
"route53:Get*",
"route53:List*",
"s3:GetAccountPublicAccessBlock",
"s3:GetBucketAcl",
"s3:GetBucketLocation",
"s3:GetBucketLogging",
"s3:GetBucketPolicy",
"s3:GetBucketPublicAccessBlock",
"s3:GetBucketVersioning",
"s3:GetEncryptionConfiguration",
"s3:GetLifecycleConfiguration",
"s3:ListAllMyBuckets",
"securityhub:Describe*",
"securityhub:Get*",
"securityhub:List*",
"sqs:GetQueueAttributes",
"sqs:GetQueueUrl",
"sqs:ListQueues",
"tag:GetResources"
],
"Resource": "*"
}
]
}