Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, 
      see Getting Started with Amazon Web Services in China
         (PDF). 
    After you add or edit tags for Amazon Security Hub CSPM resources, you can view what tag keys and tag values a resource currently has. 
            A tag is a label that you define and assign to one or more Amazon
            resources, including certain types of Macie resources. Each tag consists of a required
            tag key and an optional tag value. A tag key is a general
            label that acts as a category for a more specific tag value. A tag value acts as a descriptor for a tag key.
Tags can help you identify, categorize, and manage resources in different ways, such
	        as by purpose, owner, environment, or other criteria. For example, you can use tags to:
	        apply policies, allocate costs, distinguish between versions of resources, or identify
	        resources that support certain compliance requirements or workflows.
You can add tags to the following types of Security Hub CSPM resources:
	         
	         
	         
	    - 
	            Automation rules 
- 
	            Configuration policies 
- 
	            Hubresource
 
 You can review the tags for a Security Hub CSPM automation rule or configuration policy by
			using the Security Hub CSPM console or the Security Hub CSPM API. The console doesn't support reviewing tags for the Hub resource. 
            Programmatically, you can review tags for any resource.
To review tags for multiple Security Hub CSPM
			resources at the same time, use the tagging operations of the Amazon Resource Groups Tagging
				API.
			- Console
- 
					To review tags for a Security Hub CSPM resource (console)- Using the credentials of the Security Hub CSPM administrator, open the Amazon Security Hub CSPM console at https://console.amazonaws.cn/securityhub/. 
- 
							Depending on the type of resource that you want to add a tag to, do one of the following: 
								 
								 
							- To review the tags for an automation rule, choose Automations in the navigation pane. 
								Then, choose an automation rule. 
- To review the tags for a configuration policy, choose Configuration in the navigation pane. 
								Then, on the Policies tab, select the option next to a configuration policy. A side panel opens that 
								shows you the number of tags assigned to the policy. You can expand the Tags header to see the tag keys and tag values. 
 
 
 
The Tags section lists all the tags that are currently assigned to the resource. 
- Security Hub CSPM API
- 
					To review tags for a Security Hub CSPM resource (API) To retrieve and review the tags for an existing resource, invoke the ListTagsForResource API. In your
						request, use the resourceArnparameter to specify the Amazon
						Resource Name (ARN) of the resource.
 If you're using the Amazon CLI, run the list-tags-for-resource command and use the
							resource-arnparameter to specify the ARN of the resource.
						For example:
 $ aws securityhub list-tags-for-resource --resource-arn arn:aws-cn:securityhub:us-east-1:123456789012:configuration-policy/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111
 If the operation succeeds, Security Hub CSPM returns a tagsarray. Each object in
						the array specifies a tag (both the tag key and tag value) that's currently
						assigned to the resource. For example:
 {
    "tags": [
        {
            "key": "Environment",
            "value": "Prod"
        },
        {
            "key": "CostCenter",
            "value": "12345"
        },
        {
            "key": "Owner",
            "value": ""
        }
    ]
}
 Where Environment,CostCenter, andOwnerare the tag keys that are assigned to the resource.Prodis the tag value that's associated with theEnvironmenttag key.12345is the tag value
						that's associated with theCostCentertag key. TheOwnertag key doesn't have an associated tag value.
 To retrieve a list of all the Security Hub CSPM resources that have tags and all
						the tags that are assigned to each of those resources, use the GetResources operation of the Amazon Resource Groups Tagging API. In your
						request, set the value for the ResourceTypeFiltersparameter tosecurityhub. To do this using the Amazon CLI, run the get-resources command and set the value for theresource-type-filtersparameter tosecurityhub. For example:
 $ aws resourcegroupstaggingapi get-resources -\-resource-type-filters "securityhub"
 If the operation succeeds, Resource Groups returns a ResourceTagMappingListarray. The
						array contains one object for each Security Hub CSPM resource that has tags. Each
						object specifies the ARN of a Security Hub CSPM resource, and the tag keys and
						values that are assigned to the resource.