- Sign up to Tamnoon
- Click on Settings → Integrations. Select Security Hub

- Copy the Account Id and the external ID shown on the screen. You will need them in the steps below.

- Login to your AWS console (aws.amazon.com)
- Go to IAM-> Roles-> create Role by clicking the following link
- Under Trust Entity Type - select AWS Account
- Under “An AWS account” Section select “Another AWS Account” and enter the AccountId recorded in step 3 ****
- In Options - Select Require external ID and enter the external ID recorded in step 3:
- Click on the ‘Next‘ button at the bottom of the page
- Search for “AWSSecurityHubReadOnlyAccess” policy and select it, click “Next”
- Set the role name to TamnoonSecurityHubFetchRole and click on ‘Create Role‘ at the bottom of the page
- On the search box look for the ‘Role name‘ you set in the previous step, and click on it.