Preparing data for scanning in DSPM
To start a continuous update scan, create a scope in Interface v2.0.
Before creating a regular scan in DSPM, prepare a data source in Interface v1.0. You can also do this when creating a scan.
Getting started
Before you start using the DSPM module, set up your workspace and specify the default folder to store Data Security Posture Management (DSPM) data:
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
DSPM. -
If the Security Deck settings window opens, this means the DSPM data storage folder has not been configured. Under Choose your default folder, select a folder to store the module data by default and click Save at the bottom of the page.
-
If the DSPM UI opens, this means the module's data storage folder has already been configured, so you can continue working.
You can change the DSPM data storage folder path. To do this, navigate to the Settings tab. Under Default storage, select another folder.
-
Activate DSPM in the current workspace. To do this, click
Configure DSPM at the top right.In the window that opens, navigate to the Control modules tab. Under Control modules, select the **Data Security Posture Management (DSPM)
** module and click Save.If you have no workspaces yet, create one and activate the **Data Security Posture Management (DSPM)
** when creating the workspace.
Creating a scan scope or data source
Enabling Data Security Posture Management automatically starts data analysis in Yandex Object Storage buckets. After data analysis detects potentially dangerous resources, you can create a scan scope for them:
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
DSPM. -
On the DSPM module page, select
Interface: v2.0and navigate to the Scan scopes tab. -
Click New scan or New scan scope if you already have a scan running. The scan scope creation window will open.
-
Select the buckets, folders, or clouds you want scanned and click Add to the scan.
-
Under Resource group, specify locations requiring continuous monitoring:
- In the Resources line, specify clouds or folders:
AllorSelected. Select clouds or folders as needed. - In the Buckets line, select
All bucketsorPublic buckets. - Optionally, configure
File filter:- Add formats.
- Set maximum and minimum size limits.
- Specify a regular expression to check the path against.
Optionally, add another resource group. You can add several resource groups, each with filters of its own.
- In the Resources line, specify clouds or folders:
-
Under Data categories for search, specify the data to search in. You can select both In text and On images data. Enable
Data for searchto search for all sensitive data or select a specific data type:- In text:
Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).Financial data: Bank card details.Secrets: Cloud access keys, passwords, tokens, SSH keys, etc.
- On images:
Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).Financial data: Bank card details.Medical data: Data from medical documents and images.Other: Data from personal documents, including military IDs, pensioner IDs, academic certificates, etc.
- In text:
-
Under Scope parameters, enter a name for the scan scope in the Name field. It can describe the controlled area, include criticality, sensitive data search settings, and other useful information.
-
Click Create.
DSPM will begin continuous monitoring of changes within the scan scope for effective and targeted control of your sensitive data.
A data source contains information about the storages to scan and additional settings. The available storages are Yandex Object Storage buckets and disks
To create a data source for Object Storage and Yandex 360:
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
DSPM. -
On the DSPM** page, select
Interface: v1.0and navigate to the Data sources tab. -
In the top-right corner, click Create source
and select Object Storage or Yandex 360.Object StorageYandex 360Add the resources you want to scan to the data source:
-
To add individual buckets, click
Select bucket and select one or more buckets from available folders.You can filter buckets by access settings (
RestrictedorPublic) and by bucket name as needed. -
To add clouds or folders to your data source, click
Select cloud or catalog and select all or some of the available clouds and/or folders.After you select clouds and folders under Include in scan, select the buckets to scan:
- All buckets
The data source will include all buckets in the selected clouds and folders. In which case the scan will cover not only the buckets existing at the time you create the data source but also those you add to these clouds and folders by the time you run the scan in the future. - Public buckets
The data source will include buckets with public access configured. Only these buckets will be scanned for personal data. Disable public access for these buckets to automatically remove them from the scan.
- All buckets
-
Click Configure connection and configure integration with the Yandex 360 organization:
-
Specify the Organization 360
ID.You can look up the ID in your company profile
in the organization administrator account. -
Enter the OAuth token
. -
Optionally, to provide access to custom resources, e.g., to scan custom disks, create
a service application and specify the following properties:- ClientID
- Client secret
Note
This feature is not available for the Yandex 360 Minimum plan
. -
Click Save.
-
-
Add the resources you want to scan to the data source:
- To add shared disks to your organization, under Organization resources, click Add resources. Select or deselect disks as appropriate in one or more folders.
- To add custom disks to the data source, click Add resources under User resources. Select or deselect custom disks as appropriate.
- To add all available disks to the data source, click All disks under Organization resources or User resources. The scan will include not only the disks existing in the selected organization when the data source is created, but also disks added later (by the time of the scan).
-
-
Under Include in selection, specify one or more scan scopes:
-
All files: To scan all files saved in the buckets. -
DOC / TXT: To scan.doc,.docx, and.txttext files. -
XLS / CSV: To scan.xls,.xlsx, and.csvspreadsheet files. -
PPT: To scan.pptand.pptxpresentation files. -
PDF: To scan.pdfdocument files. -
HTML / XML: To scan.htmland.xmlfiles. -
Images: To scan.jpg,.jpeg,.png,.gif,.webp, and.svgimage files. -
Custom filter: To scan all files whose names do or do not match the specified patterns:- The file name contains: To scan files whose names match the specified pattern.
- The file name does not contain: To ignore files whose names match the specified pattern.
Specify the patterns using the RE2
regular expression syntax. You can specify patterns in both fields, in which case the scan will use theANDlogic to select files.
You can select multiple filters at the same time; the system will use the
ORlogic to apply them. -
-
If you want to add resources with different scan scope selection settings to the same data source, click Add a resource group and repeat steps
6and7in the section that appears.You can add any number of resource groups to a single data source for scanning.
-
Under Information about source, indicate the data source name you will use to select this source when creating a scan. Follow these naming requirements:
- Length: between 3 and 63 characters.
- It can only contain lowercase Latin letters, numbers, and hyphens.
- It must start with a letter and cannot end with a hyphen.
Click
on the right side of the Name field to automatically generate a name for the data source you are creating. -
Click Create source.
As a result, the new source will appear in the list of data sources. Now you can select this data source when creating a scan.