All Products
Search
Document Center

Security Center:ListCheckItem

Last Updated:Aug 07, 2026

Retrieves the list of check items that can be configured with custom settings.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request parameters

Parameter

Type

Required

Description

Example

CurrentPage

integer

No

The page number of the page to return. Default value: 1, which indicates that the first page is returned.

1

PageSize

integer

No

The maximum number of entries per page in a paged query. Default value: 20.

10

Lang

string

No

The language type for the request and response messages. Default value: zh. Valid values:

  • zh: Chinese

  • en: English

zh

TaskSources

array

No

The list of task sources.

string

No

The task source. Valid values:

  • YAO_CHI: ApsaraDB.

YAO_CHI

Response elements

Element

Type

Description

Example

object

The response struct.

CheckItems

array<object>

The list of check item information.

array<object>

The check item information.

InstanceSubType

string

The asset subtype of the cloud service. Valid values:

  • If InstanceType is set to ECS, valid values of this parameter:
    • INSTANCE

    • DISK

    • SECURITY_GROUP

  • If InstanceType is set to ACR, valid values of this parameter:
    • REPOSITORY_ENTERPRISE

    • REPOSITORY_PERSON

  • If InstanceType is set to RAM, valid values of this parameter:
    • ALIAS

    • USER

    • POLICY

    • GROUP

  • If InstanceType is set to WAF, valid values of this parameter:
    • DOMAIN

  • If InstanceType is set to other values, valid values of this parameter:
    • INSTANCE

INSTANCE

CheckId

integer

The ID of the check item.

21

CheckShowName

string

The name of the check item.

IPv4 Access Control

InstanceType

string

The asset type of the cloud service. Valid values:

  • ECS: Elastic Compute Service server

  • SLB: load balancing

  • RDS: ApsaraDB RDS database

  • MONGODB: ApsaraDB for MongoDB database

  • KVSTORE: ApsaraDB for Redis database

  • ACR: ACR

  • CSK: CSK

  • VPC: VPC

  • ACTIONTRAIL: ActionTrail

  • CDN: CDN

  • CAS: Certificate Management Service (formerly SSL Certificates)

  • RDC: Apsara Devops

  • RAM: RAM

  • DDOS: distributed deny-of-service

  • WAF: WAF

  • OSS: Access Control

  • POLARDB: POLARDB

  • POSTGRESQL: PostgreSQL

  • MSE: MSE

  • NAS: NAS

  • SDDP: SDDP

  • EIP: EIP

API_GATEWAY

RiskLevel

string

The risk level of the check item. Valid values:

  • HIGH: high

  • MEDIUM: medium

  • LOW: low

HIGH

Vendor

string

The cloud asset vendor. Valid values:

  • 0: Alibaba Cloud asset

  • 1: asset outside the cloud

  • 2: IDC asset

  • 3, 4, 5, 7: other cloud assets

  • 8: simple application server

0

SectionIds

array

The list of section IDs associated with the check item.

integer

The section ID associated with the check item.

102

Description

object

The description of the check item.

Type

string

The type of the description of the check item. Valid value:

  • text

text

Value

string

The content of the description for the check item when the Type parameter is text.

Checks whether strict access control policies are configured. Requirements: 1. If no blacklists and whitelist are configured, configure a whitelist first. 2. If a blacklist is configured, find the blacklist in the list of access control policies. We recommend that you do not configure an empty blacklist. 3. If a whitelist is configured, find the whitelist in the list of access control policies. We recommend that you do not configure an empty whitelist. Make sure that the whitelist does not contain 0.0.0.0. You can add the following IP addresses to the whitelist: ${IPList}.

CustomConfigs

array<object>

The list of custom check configuration information.

object

The custom check configuration information.

Name

string

The name of the check item.

IPList

TypeDefine

string

The type of the check item. The value is a JSON string.

{\"type\":\"LIST\",\"range\":[1,512],\"listType\":{\"type\":\"STRING\",\"range\":[0,22]}}

DefaultValue

string

The default value of the check item. The value is a string.

0

Value

string

The specified value of the check item. The value is a string.

1

ShowName

string

The display name of the check item.

IP列表

EstimatedCount

integer

The estimated number of authorizations that the check item will consume.

30

CheckType

string

The source type of the Threat Detection Service check item. Valid values:

  • CUSTOM: user-defined

  • SYSTEM: predefined by the Threat Detection Service platform

SYSTEM

InstanceEstimatedCount

integer

PageInfo

object

The page information in a paged query.

CurrentPage

integer

The page number of the current page in a paged query.

1

PageSize

integer

The number of entries per page.

10

TotalCount

integer

The total number of entries returned.

149

Count

integer

The number of entries on the current page in a paged query.

10

RequestId

string

The ID of the request, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues.

9F4E6157-9600-5588-86B9-38F09067****

Examples

Success response

JSON format

{
  "CheckItems": [
    {
      "InstanceSubType": "INSTANCE",
      "CheckId": 21,
      "CheckShowName": "IPv4 Access Control",
      "InstanceType": "API_GATEWAY",
      "RiskLevel": "HIGH",
      "Vendor": "0",
      "SectionIds": [
        102
      ],
      "Description": {
        "Type": "text",
        "Value": "Checks whether strict access control policies are configured. Requirements: 1. If no blacklists and whitelist are configured, configure a whitelist first. 2. If a blacklist is configured, find the blacklist in the list of access control policies. We recommend that you do not configure an empty blacklist. 3. If a whitelist is configured, find the whitelist in the list of access control policies. We recommend that you do not configure an empty whitelist. Make sure that the whitelist does not contain 0.0.0.0. You can add the following IP addresses to the whitelist: ${IPList}."
      },
      "CustomConfigs": [
        {
          "Name": "IPList",
          "TypeDefine": "{\\\"type\\\":\\\"LIST\\\",\\\"range\\\":[1,512],\\\"listType\\\":{\\\"type\\\":\\\"STRING\\\",\\\"range\\\":[0,22]}}",
          "DefaultValue": "0",
          "Value": "1",
          "ShowName": "IP列表"
        }
      ],
      "EstimatedCount": 30,
      "CheckType": "SYSTEM",
      "InstanceEstimatedCount": 0
    }
  ],
  "PageInfo": {
    "CurrentPage": 1,
    "PageSize": 10,
    "TotalCount": 149,
    "Count": 10
  },
  "RequestId": "9F4E6157-9600-5588-86B9-38F09067****"
}

Error codes

HTTP status code

Error code

Error message

Description

500 ServerError ServerError
403 NoPermission caller has no permission

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.