The ID of the only AWS resource that you want your control scope to contain.
Describes whether the control scope includes one or more types of resources, such as EFS or RDS.
Tag key-value pair applied to those AWS resources that you want to trigger an evaluation for a rule. A maximum of one key-value pair can be provided.