Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Automate the AWS Security Hub finding updates and closures by the SIR incident status

Automate the updates and closures of findings on AWS Security Hub according to the SIR incident status. The AWS Security Hub integration has a bi-directional interface that enables findings ingestion to create security incidents and to update the findings' status according to the changes in the SIR incident.

Before you begin

Role required: sn_si.admin

Procedure

  1. On the form, fill in the details.

    Follow the instructions to complete the configuration for updating AWS Security Hub findings when you create or close a security incident in SIR.

CategoryFieldDescription
Update StateSIR Incident StateDisplays a list of SIR incident states. Select an option from this list to map it to a Security Hub Finding State.
Security Hub Finding StateDisplays a list of Security Hub workflow statuses.The workflow status of a finding is updated on AWS Security Hub when the corresponding SIR state incident state changes.
Update PrioritySIR Incident PriorityDisplays a list of SIR incident priority levels. Select an option from this list to map it to a Security Hub finding priority level.
Security Hub Finding PrioritySelect an option from the list of Security Hub severity levels.The severity of a finding is updated on AWS Security Hub when the corresponding security incident priority changes.
Update Work NotesSelect this option to update the notes section of aSecurity Hub when a work note is updated for the correspondingSIR incident.The work notes section on SIR has a limit of 512 characters as the notes section of a Security Hub finding supports the same.
Update Additional CommentsSelect to update the AWS Security Hub finding comments section with the additional comments you provided in SIR incident.
Update Resolution NotesSelect to update the AWS Security Hub closing comments section with the resolution notes you provided when the SIR incident is resolved.
**Note:** Each update from the work notes overrides the last update in the notes section of a Security Hub finding. We recommend you to add relevant work notes in a SIR incident.
  1. Select Finish.

What to do next

The profile moves to the Waiting state. When the confirmation message shows that the setup and configuration is complete, you can activate the profile.