All Products
Search
Document Center

Security Center:DescribeStrategyDetail

Last Updated:Jun 17, 2026

Retrieves the details of a baseline check policy.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeStrategyDetail

get

*BaselineStrategy

acs:yundun-sas:{#regionId}:{#accountId}:baselinestrategy/{#BaselineStrategyId}

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The IP address of the access source.

192.168.XX.XX

Lang

string

No

The language type for the request and response messages. Default value: zh. Valid values:

  • zh: Chinese

  • en: English.

zh

Id

string

Yes

The ID of the baseline check policy.

123456

Response elements

Element

Type

Description

Example

object

The response data for the baseline check policy details.

RequestId

string

The ID of the request. Alibaba Cloud generates a unique identifier for each request. You can use the ID to troubleshoot issues.

C5B28F65-9245-5DC1-B3CF-5F2756A756A8

Strategy

object

The information about the policy.

Type

integer

The type of the policy. Valid values:

  • 1: system-added policy. The policy name is the default policy.

  • 2: user-added policy.

1

CycleDays

integer

The detection cycle of the policy.

3

Name

string

The Policy Name.

TestStrategy

Id

integer

The ID of the policy.

123

CycleStartTime

integer

The detection cycle of the policy. Valid values:

  • 0: 00:00 to 06:00

  • 6: 06:00 to 12:00

  • 12: 12:00 to 18:00

  • 18: 18:00 to 24:00.

0

RiskTypeWhiteListQueryResultList

array<object>

The list of risk item whitelists.

array<object>

The risk item whitelist.

TypeName

string

The name of the check item.

hc_exploit

Alias

string

The alias of the check item.

Unauthorized Access

On

boolean

Indicates whether the check item is selected. Valid values:

  • true

  • false

false

SubTypes

array<object>

The information about sub-check items.

array<object>

TypeName

string

The type of the sub-check item.

hc_exploit_redis

Alias

string

The alias of the check item.

Redis unauthorized access high exploit vulnerability risk

On

boolean

Indicates whether the sub-check item is selected. Valid values:

  • true

  • false

false

CheckDetails

array<object>

The details of custom check items.

array<object>

CheckId

integer

The ID of the check item.

206

CheckItem

string

The check item.

Ensure password expiration period is set.

CheckDesc

string

The description of the check item.

Set password expiration time, force regular modification of password, reduce password leakage and guess risk.Use non-password login (e.g. key pair) please ignore this item.

Rules

array<object>

The details of rules.

array<object>

Optional

integer

Indicates whether the rule can be selected. Valid values:

  • 1: yes

  • 0: no

1

RuleDesc

string

The description of the rule.

Please customize the password expiration time detection standard as

DefaultValue

integer

The default value of the rule.

2

RuleId

string

The rule ID.

login_unlock_deny_pam_faillock.must.cus

ParamList

array<object>

The rule parameters.

object

The information about the rule parameter.

ParamDefaultValue

string

The default value of the rule parameter.

7

Value

string

The configured value of the rule parameter.

7

ParamName

string

The name of the rule parameter.

range_val

MaxValue

integer

The maximum value of the rule parameter.

999

ParamType

integer

The type of the rule parameter. Valid values:

  • 1: input

  • 2: selection

1

ParamDesc

string

The description of the rule parameter.

The setting value is 0 means no definition, 1 means success, 2 means failure, 3 means success and failure

MinValue

integer

The minimum value of the rule parameter.

1

EnumValue

string

The options that can be selected for the rule parameter if the value of ParamType is set to 2.

0,1,2,3

SupportedOs

string

The operating system type of the server. Valid values:

  • windows

  • linux

windows

StartTime

string

The start time of the baseline check policy.

02:00:00

EndTime

string

The end time of the baseline check policy execution.

03:00:00

CustomType

string

The type of the policy. Valid values:

  • common: Standard policy.

  • custom: Custom policy.

common

TargetType

string

The method used to add assets to the policy. Valid values:

  • groupId: Assets are added by asset group.

  • uuid: Assets are added individually.

groupId

RiskSubTypeName

string

The subtype of the baseline check item.

hc_nginx_linux,tomcat7,hc_mysql_ali,hc_docker

Examples

Success response

JSON format

{
  "RequestId": "C5B28F65-9245-5DC1-B3CF-5F2756A756A8",
  "Strategy": {
    "Type": 1,
    "CycleDays": 3,
    "Name": "TestStrategy",
    "Id": 123,
    "CycleStartTime": 0,
    "RiskTypeWhiteListQueryResultList": [
      {
        "TypeName": "hc_exploit",
        "Alias": "Unauthorized Access",
        "On": false,
        "SubTypes": [
          {
            "TypeName": "hc_exploit_redis",
            "Alias": "Redis unauthorized access high exploit vulnerability risk",
            "On": false,
            "CheckDetails": [
              {
                "CheckId": 206,
                "CheckItem": "Ensure password expiration period is set.",
                "CheckDesc": "Set password expiration time, force regular modification of password, reduce password leakage and guess risk.Use non-password login (e.g. key pair) please ignore this item.",
                "Rules": [
                  {
                    "Optional": 1,
                    "RuleDesc": "Please customize the password expiration time detection standard as",
                    "DefaultValue": 2,
                    "RuleId": "login_unlock_deny_pam_faillock.must.cus",
                    "ParamList": [
                      {
                        "ParamDefaultValue": "7",
                        "Value": "7",
                        "ParamName": "range_val",
                        "MaxValue": 999,
                        "ParamType": 1,
                        "ParamDesc": "The setting value is 0 means no definition, 1 means success, 2 means failure, 3 means success and failure",
                        "MinValue": 1,
                        "EnumValue": "0,1,2,3"
                      }
                    ]
                  }
                ]
              }
            ],
            "SupportedOs": "windows"
          }
        ]
      }
    ],
    "StartTime": "02:00:00",
    "EndTime": "03:00:00",
    "CustomType": "common",
    "TargetType": "groupId",
    "RiskSubTypeName": "hc_nginx_linux,tomcat7,hc_mysql_ali,hc_docker"
  }
}

Error codes

HTTP status code

Error code

Error message

Description

500 ServerError ServerError
403 NoPermission caller has no permission

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.