Resource Matrix
InsightCloudSec uses standardized language (aka normalized terminology) to describe virtual/software-defined resources across public and private cloud technologies. The table below includes the name of each Resource as it appears in the InsightCloudSec platform, the category of resource, and the CSP-specific name (where applicable).
Supported Services & Regions
In general, InsightCloudSec provides support for the resources listed below for all regions in which they are available. In some scenarios some resources or services may not be available in certain regions. This is typically the result of restrictions related to the region itself or otherwise imposed by the CSP (e.g., AWS) to comply with regional policies. We recommend that you refer to the CSP-specific documentation on those specific regions for official details.
(For example, refer to the table for AWS services in China here.)
If you have other questions related to regions, or specific services and their support, contact us through the Customer Support Portal with any questions.
Azure Data Lake Storage Gen1 Retired
As of February 29, 2024, Azure has retired the Data Lake Storage Gen1 service. The Data Lake Storage resource type has been disabled until InsightCloudSec is able to officially support Azure Data Lake Storage Gen2. Contact support for any questions or issues.
Resource Type | Category | Amazon Web Services (AWS) | AWS GovCloud | Microsoft Azure | Google Cloud Platform (GCP) | Alibaba Cloud | Kubernetes | Oracle (OCI) | |
---|---|---|---|---|---|---|---|---|---|
Access Analyzer | Identity and Management | AWS IAM Access Analyzer | |||||||
Access List | Network | NACL / Security Group | NACL / Security Group | Network Security Group | Network Firewall | Security Group | Network Security Group/Security List | ||
Access List Flow Log | Network | NSG (Network Security Group) Flow Log | |||||||
Access List Rule | Network | Rules | Rules | Security Rules | Firewall Rules | Rules | Network Security Group Rule/Security List Rule | ||
Activity Log Alert | Identity and Management | Activity Log Alert | |||||||
Airflow Environment | Compute | Managed Airflow Environment | Cloud Composer | ||||||
API Access Key | Identity and Management | Access key ID | Access key ID | Application Credentials | Service Account Key | Access Key ID | |||
API Accounting Config | Identity and Management | CloudTrail | CloudTrail | N/A | Logs Storage | ActionTrail | |||
API Key Usage Plan | Network | API Key Usage Plan | API Key Usage Plan | ||||||
App Configuration | Compute | App Configuration | |||||||
App Engine Service | Compute | App Engine Service | |||||||
App Engine Service Version | Compute | App Engine Service Version | |||||||
App Run Service | Containers | AWS App Runner | Cloud Run | ||||||
App Server | Compute | App Service Plan | |||||||
App Stream Fleet | Compute | AppStream 2.0 | AppStream 2.0 | ||||||
Application Gateway | Network | API Gateway | API Management Service | ||||||
Application Gateway Domain | Network | API Gateway Domain | |||||||
Application Key | Network | API Gateway Key | |||||||
Application Stage | Network | API Gateway Stage | |||||||
Artifact Registry | Containers | Artifact Registry | |||||||
Automation Account | Machine Learning & AI | Automation Account | |||||||
Autoscaling Group | Compute | Autoscaling Group | Autoscaling Group | Virtual Machine Scale Sets | Autoscalers | N/A | |||
Autoscaling Launch Configuration | Compute | Launch Configurations | N/A | N/A | N/A | N/A | |||
Azure Policy | Identity and Management | Azure Policy | |||||||
Backend Services | Compute | Load Balancer Backend Services | |||||||
Backup Gateway | Storage | Backup Gateway | Backup Gateway | ||||||
Backup Vault | Storage | Backup Vault | N/A | ||||||
Bastion Host | Network | Bastion Host | |||||||
Batch Environment | Compute | Batch Compute Environment | Batch Compute Environment | Batch Account | |||||
Batch Pool | Compute | Batch Pool | |||||||
Bedrock Agent | Machine Learning & AI | Bedrock Agent | |||||||
Bedrock Model | Machine Learning & AI | Bedrock Model | |||||||
Bedrock Training Job | Machine Learning & AI | Bedrock Job | |||||||
Big Data Instance | Compute | Redshift | Redshift | ||||||
Big Data Serverless Namespace | Compute | Redshift Serverless Namespace | |||||||
Big Data Serverless Workgroup | Compute | Redshift Serverless Workgroup | |||||||
Big Data Snapshot | Storage | Redshift Snapshot | Redshift Snapshot | N/A | N/A | N/A | |||
Big Data Workspace | Compute | Azure Synapse | |||||||
Bot Service | Machine Learning & AI | Bot Service | |||||||
Build Project | Compute | CodeBuild Project | CodeBuild | ||||||
Business Intelligence Subscription | Identity and Management | QuickSight | QuickSight | N/A | |||||
Cache Database Cluster | Compute | MemoryDB | MemoryDB | ||||||
Cache Instance | Compute | ElastiCache | Elasticache | Azure Redis | Memorystore | AsparaDB for Redis | |||
Cache Snapshot | Storage | ElastiCache Snapshot | Redis Snapshot | ||||||
Cassandra Table | Storage | Keyspaces Table | Keyspaces Table | ||||||
Cloud Access Point | Identity and Management | S3 Access Point | S3 Access Point | ||||||
Cloud Account | Identity and Management | Cloud Account | Cloud Account | Cloud Subscription | Project | Cloud Account | Cloud Tenancy | ||
Cloud Advisor Check | Identity and Management | Trusted Advisor | Trusted Advisor | Security Command Center Baseline | N/A | ||||
Cloud Alarm | Identity and Management | CloudWatch Alarm | CloudWatch Alarm | N/A | N/A | N/A | |||
Cloud App | Identity and Management | Azure App Registration | |||||||
Cloud Credentials | Identity and Management | API Keys | |||||||
Cloud Dataset | Storage | BigQuery Dataset | |||||||
Cloud Domain Group | Identity and Management | N/A | N/A | N/A | Domain Groups | ||||
Cloud Domain User | Identity and Management | N/A | N/A | Domain Users | |||||
Cloud Event Bus | Identity and Management | CloudWatch/Event Bridge Event Bus | CloudWatch/Event Bridge Event Bus | ||||||
Cloud Event Rule | Identity and Management | CloudWatch Rule | CloudWatch Rule | ||||||
Cloud Global Access Point | Storage | S3 Multi-Region Access Point | |||||||
Cloud Group | Identity and Management | IAM Group | IAM Group | Group | Group | RAM Group | Group | ||
Cloud Limit | Identity and Management | Limit | Limit | Limit | Limit | N/A | |||
Cloud Log Destination | Identity and Management | CloudWatch Logs Destinations | CloudWatch Logs Destinations | ||||||
Cloud Outpost | Identity and Management | Outpost | |||||||
Cloud Policy | Identity and Management | IAM Policy | IAM Policy | Policy | Role Permission Set | RAM Policy | |||
Cloud Region | Identity and Management | Region | Region | Region | Region | Region | Region | ||
Cloud Resource Group | Identity and Management | Azure Resource Group | |||||||
Cloud Role | Identity and Management | IAM Role | IAM Role | Role | Service Account | RAM Role | |||
Cloud Role Assignment | Identity and Management | Azure Role Assignment | |||||||
Cloud Service Cost | Identity and Management | Consolidated Bill | Consolidated Bill | N/A | Billing Export | ||||
Cloud User | Identity and Management | IAM User | IAM User | User | User | RAM User | User | ||
Cluster Role | Containers | Cluster Role | |||||||
Clusters | Containers | EKS/ECS/Fargate Cluster | EKS/ECS/Fargate Cluster | Kubernetes Service | GKE | Kubernetes Cluster | Kubernetes Cluster | ||
Code Repository | Identity and Management | Code Commit | Code Commit | ||||||
Cognitive Search | Machine Learning & AI | Cognitive Search | |||||||
Cold Storage | Storage | Glacier | N/A | N/A | N/A | N/A | |||
Collaboration | Identity and Management | Clean Rooms | Clean Rooms | ||||||
Computer Vision | Machine Learning & AI | Computer Vision | |||||||
Conditional Access Policy | Identity and Management | Conditional Access Policy | |||||||
Config | Identity and Management | AWS Config | AWS Config | ||||||
Config Map | Containers | Config Map | Config Map | ||||||
Connect Instance | Compute | Amazon Connect | Amazon Connect | ||||||
Container Image | Containers | Container Image (ECR) | Container Image (ECR) | Container Image | Container Image | ||||
Container Instances | Containers | Container Instance (ECS) | Container Instance (ECS) | Azure Container Instance | Node Instance | ||||
Container Node Group | Containers | EKS Node Group | EKS Node Group | ||||||
Container Registry | Containers | Container Registry (ECR) | Container Registry (ECR) | Container Registry | |||||
Container Service | Containers | ECS Service | ECS Service | ||||||
Containers | Containers | Container | Container | Container | |||||
Content Delivery Network | Network | CloudFront | CloudFront | CDN Profile, Front Door (Standard/Premium) | Cloud CDN | N/A | |||
Content Moderator | Machine Learning & AI | Content Moderator | |||||||
Control Plane | Containers | Control Plane | |||||||
Control Policy | Identity and Management | Organization Policy | |||||||
Control Tower Control | Identity and Management | Control Tower Control | Control Tower Control | ||||||
Control Tower Landing Zone | Identity and Management | Control Tower Landing Zone | Control Tower Landing Zone | ||||||
Cron Jobs | Containers | Cron Jobs | |||||||
DaemonSet | Containers | DaemonSet | |||||||
Data Analytics Workspace | Storage | Athena Workgroup | Athena Workgroup | ||||||
Data Factory | Storage | Azure Data Factory | Data Fusion | ||||||
Data Stream | Storage | Kinesis | Kinesis | Event Hub Namespace | N/A | N/A | |||
Data Sync Task | Storage | DataSync Task | |||||||
Database | Compute | N/A | N/A | SQL Database / Dedicated SQL Pool | Cloud SQL Database | ||||
Database Cluster | Compute | RDS Database, Neptune, DocumentDB | |||||||
Database Event Subscription | Compute | RDS Event Subscription | |||||||
Database Instance | Compute | RDS Database, Neptune, DocumentDB | RDS Database | Azure Database for Postgres/MySQL/MariaDB | Cloud SQL | AsparaDB for RDS | MySQL DB System/Autonomous Data Warehouse | ||
Database Migration Instance | Storage | DMS Replication Instance | DMS Replication Instance | ||||||
Database Migration Endpoint | Network | DMS Endpoint | DMS Endpoint | ||||||
Database Proxy | Storage | RDS Database Proxy | RDS Database Proxy | ||||||
Database Snapshot | Storage | RDS Snapshot | RDS Snapshot | N/A | Cloud SQL Backup | RDS Snapshot | |||
Databricks Workspace | Storage | Databricks Workspace | |||||||
Dataflow Job | Compute | Dataflow Jobs | |||||||
DDoS Protection | Network | Shield | DDoS Protection | ||||||
Delivery Stream | Storage | Firehose | N/A | N/A | N/A | ||||
Deployments/Tasks | Containers | Container Pod (ECS/Fargate) | Deployment | ||||||
Diagnostic Settings | Identity and Management | Diagnostic Settings | |||||||
Direct Connect | Network | Direct Connect | Express Route Circuit | Cloud Interconnect | |||||
Directory Service | Identity and Management | AWS Directory Service | |||||||
Distributed Table | Compute | DynamoDB | DynamoDB | Azure CosmosDB | N/A | N/A | NoSQL Database | ||
Distributed Table Cluster | Compute | Dynamo DB Accelerator (DAX) | N/A | Bigtable | N/A | ||||
DLP Job | Compute | DLP Inspection Job | |||||||
DNS Domain | Identity and Management | Route53 Domain | Cloud Domain | ||||||
DNS Zone | Network | Route53 DNS Zone | DNS Zone | DNS Zone | N/A | ||||
Elastic Cluster | Storage | DocumentDB Elastic | |||||||
Elasticsearch Instance | Compute | OpenSearch | OpenSearch | N/A | N/A | N/A | |||
Elasticsearch Serverless Collection | Compute | OpenSearch Collection | |||||||
Email Service Config | Compute | Simple Email Service Configuration Set (SES) | Simple Email Service Configuration Set (SES) | ||||||
Email Service Domain | Compute | Simple Email Service (SES) | Simple Email Service (SES) | N/A | N/A | N/A | R | ||
Email Service Rule | Compute | Simple Email Service Rule (SES) | Simple Email Service Rule (SES) | ||||||
Encryption Key | Identity and Management | KMS | KMS | Key Vault Key | Cloud KMS Cryptokey | KMS Key | Master Encryption Key | ||
Encryption Key Vault | Identity and Management | Key Vault | Cloud KMS Keyring | Vault | |||||
ETL Connection | Storage | Glue Connection | Glue Connection | ||||||
ETL Crawler | Storage | Glue Crawler | Glue Crawler | ||||||
ETL Data Catalog | Storage | Glue Data Catalog | Glue Data Catalog | ||||||
ETL Database | Storage | Glue Database | Glue Database | ||||||
ETL Job | Storage | Glue Job | Glue Job | ||||||
ETL Security Configuration | Storage | Glue Security Configuration | Glue Security Configuration | ||||||
Event Grid Subscription | Compute | Event Grid Subscription | |||||||
Event Grid System Topic | Compute | Event Grid System Topic | |||||||
Event Grid Topic | Compute | Event Grid Topic | |||||||
Event Subscription | Compute | RDS Event Subscription | RDS Event Subscription | ||||||
Federated Group | Identity and Management | Federated Azure AD Group | |||||||
Federated User | Identity and Management | Federated Azure AD User | |||||||
File Share | Storage | NFS/SMB File Gateway Share | |||||||
Forwarding Rules | Network | Load Balancer Forwarding Rules | |||||||
Gatekeeper Constraint | Containers | Constraint | |||||||
Gatekeeper ConstraintTemplate | Containers | ConstraintTemplate | |||||||
Global Load Balancer | Network | Global Accelerator | Global Accelerator | Front Door | |||||
GraphQL API | Storage | AppSync API | N/A | ||||||
HSM Cluster | Compute | CloudHSM | CloudHSM | ||||||
Hypervisor | Compute | Dedicated Instance | Dedicated Instance | Dedicated Host | N/A | N/A | |||
Identity Provider | Identity and Management | SAML Identity Provider | Identity Platform Provider | ||||||
Ingress | Containers | N/A | N/A | Ingress | |||||
Instance | Compute | EC2 Instance | EC2 Instance | Virtual Machine | Compute Engine | ECS Instance | Instance | ||
Internet Gateway | Network | Internet Gateway | Internet Gateway | N/A | N/A | N/A | |||
Jobs | Containers | Jobs | |||||||
K8S Secret | Containers | Secret | |||||||
Language Service | Machine Learning & AI | Language Service | |||||||
Launch Template | Compute | Launch Template | Launch Template | ||||||
Lightsail | Compute | Amazon Lightsail | N/A | ||||||
Load Balancer | Network | Load Balancer (ELB/ALB/NLB/Gateway) | ELB/ALB/NLB | Load Balancer/Application Gateway | Load Balancer | Load Balancer (SLB/ALB/NLB/CLB) | |||
Logic App | Compute | Logic App | |||||||
Log Analytics Workspace | Identity and Management | Log Analytics Workspace | |||||||
Log Group | Identity and Management | CloudWatch Log Group | |||||||
Lookout Project | Identity and Management | Lookout Equipment/Metrics/Vision | N/A | ||||||
LUIS API | Machine Learning & AI | LUIS API | |||||||
Machine Learning Instance | Machine Learning & AI | Sagemaker Notebook | Sagemaker Notebook | AI Platform Notebook | |||||
Machine Learning Training Job | Machine Learning & AI | Sagemaker Training job | Sagemaker Training Job | ||||||
MapReduce Cluster | Compute | Elastic Mapreduce (EMR) | Elastic Mapreduce (EMR) | HDInsight Cluster | Dataproc | N/A | |||
Message Broker Instance | Compute | MQ | |||||||
Message Queue | Compute | Simple Queue Service (SQS) | Simple Queue Service (SQS) | Service Bus Queue | N/A | N/A | |||
Message Queue Namespace | Compute | Service Bus | |||||||
Mutating Webhook Configuration | Containers | Mutating Webhook Configuration | |||||||
Named Location | Identity and Management | Named Location | |||||||
Namespace | Containers | Namespace | |||||||
NAT Gateway | Network | NAT Gateway (VPC) | N/A | NAT Gateway | Cloud NAT | N/A | |||
Network | Network | VPC | VPC | Virtual Network | VPC | VCN | |||
Network Address Group | Network | Managed Prefix List | Managed Prefix List | IP Group | |||||
Network Endpoint | Network | VPC Endpoint/PrivateLink | Service Endpoint/Service Endpoint Policy/Private Endpoint | ||||||
Network Endpoint Service | Network | VPC Endpoint Service | Private Link Service | ||||||
Network Firewall | Network | Network Firewall | Network Firewall | Azure Firewall | |||||
Network Firewall Rule | Network | Network Firewall Rule | Network Firewall Rule | Azure Firewall Rule | |||||
Network Firewall Rule List | Network | Network Firewall Rule Group | Network Firewall Rule Group | Azure Firewall Rule Collection | |||||
Network Flow Log | Network | VPC Flow Log (VPC) | VPC Flow Log (VPC) | Logging Bucket | |||||
Network Interface | Network | Network Interface | Network Interface | Network Interface | Network Interface | Network Interface | VCS Interface | ||
Network Peer | Network | VPC Peer | VPC Peer | Peerings | Network Peer | N/A | |||
Network Policy | Containers | Network Policy | |||||||
Notification Subscription | Compute | SNS Subscription | SNS Subscription | N/A | Pub / Sub Subscription | N/A | Subscription | ||
Notification Topic | Compute | SNS Topic | SNS Topic | N/A | Pub / Sub Topic | N/A | Topic | ||
Open AI | Machine Learning & AI | Open AI | |||||||
Persistent Volume | Containers | Persistent Volume | |||||||
Personalizer | Machine Learning & AI | Personalizer | |||||||
Pod Security Policies | Containers | Pod Security Policy | |||||||
Pods | Containers | Task Definition (ECS) | Pod | ||||||
Private Image | Compute | AMI (Private) | AMI (Private) | Image | Image | Image | |||
Private Subnet | Network | VPC Subnet | VPC Subnet | Subnet | Subnet | VSwitch | VCN Subnet | ||
Public IP | Network | Elastic IP | Elastic IP | Reserved IP | Reserved IP | Elastic IP | Public IP | ||
Query Log Config | Network | Route53 Resolver | Route53 Resolver | ||||||
Recommendation | Identity and Management | Unattended Project Recommendations | |||||||
Recommendation Finding | Identity and Management | Unattended Project Insights | |||||||
Recycle Bin Rule | Storage | Recycle Bin Rule | |||||||
ReplicaSet | Containers | ReplicaSet | |||||||
Reserved Instance | Compute | Reserved Instance | Reserved Instance | N/A | N/A | N/A | |||
Resource Share | Identity and Management | RAM (Resource Shares) | RAM (Resource Shares) | ||||||
Resource Share Resource | Identity and Management | RAM (Resources) | RAM (Resources) | ||||||
Role | Containers | Role | |||||||
Route | Network | Route | Route | ||||||
Route Table | Network | Route Table | N/A | Route Table | Route Table | Route Table | |||
Search Cluster | Compute | Cloudsearch Cluster | Cloudsearch Cluster | ||||||
Search Index | Compute | Kendra Index | N/A | ||||||
Secret | Identity and Management | Secret | N/A | Secret | Secret | N/A | Secret | ||
Secure File Transfer | Storage | SFTP Server | |||||||
Security Posture | Identity and Management | Azure Advisor Recommendations | |||||||
Serverless Application | Compute | Serverless Application Repository | |||||||
Serverless Function | Compute | Lambda | Lambda | Function | Cloud Function | N/A | |||
Serverless Layer | Compute | Lambda Layer | Lambda Layer | ||||||
Service Account | Containers | Service Account | |||||||
Service Control Policy | Identity and Management | Service Control Policy | |||||||
Service Detector | Identity and Management | ||||||||
Service Fabric Cluster | Containers | Service Fabric Cluster | |||||||
Service Health Event | Identity and Management | Health Dashboard | Health Dashboard | ||||||
Services | Containers | Service | |||||||
Shared Gallery | Compute | Shared Image Gallery | |||||||
Shared Gallery Image | Compute | Image Definition | |||||||
Shared Gallery Image Version | Compute | Image Version | |||||||
Shared File System | Storage | EFS, Lustre, FSx, and NetApp ONTAP | N/A | File Share | Cloud Filestore | N/A | File System | ||
Simple Log Service | Identity and Management | Simple Log Service | |||||||
Sink | Identity and Management | CloudWatch Observability Sink Link | Stackdriver Sink | ||||||
Site-to-Site VPN | Network | Site-to-Site VPN (VPC) | VPN Tunnel | ||||||
Snapshot | Storage | EBS Snapshot | EBS Snapshot | Snapshot | Snapshot | Snapshot | Block Volume Backup | ||
Spanner | Storage | Aurora Global Database | Aurora Global Database | Cloud Spanner | |||||
Speech Services | Machine Learning & AI | Speech Services | |||||||
SSH Key Pair | Identity and Management | SSH Key Pair | SSH Key Pair | SSH Key Pair | SSH Key Pair | SSH Key Pair | |||
SSL Certificate | Identity and Management | IAM/ACM SSL Certificate | IAM/ACM SSL Certificate | SSL Certificate | SSL Certificate | N/A | SSL Certificate | ||
SSL Certificate Authority | Identity and Management | ACM Private Certificate Authority | ACM Private Certificate Authority | Certificate Authority Service | |||||
SSM Association | Compute | SSM Association | SSM Association | ||||||
SSM Document | Compute | SSM Document | SSM Document | ||||||
Stack Template | Compute | CloudFormation Templates | CloudFormation Templates | ||||||
StatefulSet | Containers | StatefulSet | |||||||
Step Function | Compute | Step Function State Machine | Step Function State Machine | ||||||
Storage Account | Storage | Storage Account | |||||||
Storage Gateway | Storage | Storage Gateway | Storage Gateway | ||||||
Storage Container | Storage | S3 Bucket | S3 Bucket | Blob Storage Container | Cloud Storage | Object Storage Bucket | Object Storage Backup | ||
Storage Queue | Storage | Storage Queue | |||||||
Storage Sync Service | Storage | Storage Sync Service | |||||||
Stored Parameter | Storage | Systems Manager Parameter Store (Parameter) | |||||||
Stream Instance | Compute | MSK Instance | |||||||
Streaming Application | Compute | Kinesis Analytics Application | Kinesis Analytics Application | ||||||
Target Proxies | Network | Load Balancer Target Proxies | |||||||
Task Definitions | Container | Task Definition (ECS) | |||||||
Template Spec | Compute | Template Specs | |||||||
Threat Findings | Identity and Management | GuardDuty/Macie | Microsoft Defender for Cloud | Event Threat Detection | |||||
Timeseries Database | Storage | Amazon Timestream | |||||||
Traffic Manager | Network | Traffic Manager | |||||||
Traffic Mirror Target | Network | VPC Traffic Mirror Target | VPC Traffic Mirror Targets | ||||||
Transcoding Pipeline | Compute | Elastic Transcoder Pipeline | |||||||
Transcription Job | Compute | Transcription Job | Transcription Job | ||||||
Transit Gateway | Network | Transit Gateway | |||||||
Translator | Machine Learning & AI | Translator | |||||||
URL Map | Network | URL Map | |||||||
User Pool | Identity and Management | Cognito User Pool | |||||||
Validating Webhook Configuration | Containers | Validating Webhook Configuration | |||||||
Vertex Custom Job | Machine Learning & AI | Vertex Custom Job | |||||||
Video Stream | Storage | Kinesis Video Stream | |||||||
Virtual Private Gateway | Network | Virtual Private Gateway | Virtual Network Gateway | VPN Gateway | |||||
Volume | Storage | EBS Volume | EBS Volume | Disk | Persistent Disk | Disk | Block Volume | ||
Web App | Compute | Elastic Beanstalk Environment | App Service | ||||||
Web App Group | Compute | Elastic Beanstalk Application | |||||||
Web Application Firewall | Network | Web Application Firewall | Web Application Firewall | Web Application Firewall Policies | Cloud Armor | ||||
Web Application Firewall Rule | Network | Web Application Firewall Rule | Web Application Firewall Rule | ||||||
Web Application Firewall Group | Network | Web Application Firewall Rule Group | Web Application Firewall Rule Group | ||||||
Workspace | Compute | Workspace | N/A | N/A | N/A | N/A |