Security Command Center 會使用 Identity and Access Management (IAM),控管資源階層中不同層級的資源存取權。您可以使用 IAM 角色,控管在 Security Command Center 環境中,哪些人員可以針對資產、發現項目和安全性來源進行哪些操作。您可以將角色授予個人和應用程式,每個角色都提供特定權限。
您需要的 IAM 角色取決於啟用 Security Command Center 的層級。您可以在機構或專案層級啟用 Security Command Center。如要瞭解這兩個啟用層級的差異,請參閱「啟用 Security Command Center 的簡介」。
如何查看存取權控管資訊
如要瞭解使用 Security Command Center 時所需的 IAM 角色,請參閱下列其中一個頁面,視您啟用 Security Command Center 的層級而定:
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-05 (世界標準時間)。"],[],[],null,["| Standard, Premium, and Enterprise [service tiers](/security-command-center/docs/service-tiers)\n\nThis page describes where to find access control information for\nSecurity Command Center.\n\nSecurity Command Center uses Identity and Access Management (IAM) to control\naccess to resources at different levels of your resource hierarchy. You use\nIAM roles to control who can do what with assets,\nfindings, and security sources in your Security Command Center environment. You grant\nroles to individuals and applications, and each role provides specific\npermissions.\n\nThe IAM roles that you need depend on the level at which\nyou activated Security Command Center. You can activate Security Command Center at the\norganization level or the project level. For information about the differences\nbetween the two activation levels, see [Overview of activating\nSecurity Command Center](/security-command-center/docs/activate-scc-overview).\n\nWhere to find access control information\n\nFor information about the IAM roles that you need to use\nSecurity Command Center, see one of the following pages depending on the level at\nwhich you activated Security Command Center:\n\n- [IAM for organization-level activations of\n Security Command Center](/security-command-center/docs/access-control-org)\n\n- [IAM for project-level activations of\n Security Command Center](/security-command-center/docs/access-control-project)"]]