Creating a DSPM data source
Note
This feature is in the Preview stage. To get access, contact tech support
A data source contains information about the storages to scan and additional settings. The available storages are Yandex Object Storage buckets and Yandex Disk
Before you start using DSPM, set up the default folder to store Security Deck data.
Creating a data source for Object Storage
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Data Security Posture Management and go to the Data sources tab. -
In the top-right corner, click Create source.
-
Add the resources you want to scan to the data source:
-
To add individual buckets, click
Select bucket and select one or more buckets from one or more of your available folders.If required, use filters by access settings (
LimitedorPublic) and by bucket name. -
To add clouds or folders to your data source, click
Select cloud or folder and select all or some of the clouds and/or folders available to you.All buckets in the selected clouds and/or folders will be added to the data source. In this case, DSPM will scan both the buckets that already exist in these clouds and folders and any other buckets added to them by the time the scan is run.
-
-
Under Include in selection, specify one or more scan scopes:
-
All files: To scan all files saved in the buckets. -
DOC/TXT: To scan.doc,.docx, and.txttext files. -
XLS/CSV: To scan.xls,.xlsx, and.csvspreadsheet files. -
PPT: To scan.pptand.pptxpresentation files. -
PDF: To scan.pdfdocument files. -
HTML/XML: To scan.htmland.xmlfiles. -
Images: To scan.jpg,.jpeg,.png,.gif,.webp, and.svgimage files. -
Custom filter: To scan all files whose names do or do not match the specified patterns:- File name contains: To scan files whose names match the specified pattern.
- File name does not contain: To ignore files whose names match the specified pattern.
Specify the patterns using the RE2
regular expression syntax. You can specify patterns in both fields, in which case the scan will use theANDlogic to select files.
You can select multiple filters at the same time; the system will use the
ORlogic to apply them. -
-
If you want to add resources with different scan scope selection settings to the same data source, click Add resource group and repeat steps
4and5in the section that appears.You can add any number of resource groups to a single data source for scanning.
-
Under Information about source, indicate the data source name you will use to select this source when creating a scan. Follow these naming requirements:
- It must be from 2 to 63 characters long.
- It can only contain lowercase Latin letters, numbers, and hyphens.
- It must start with a letter and cannot end with a hyphen.
Click
on the right side of the Name field to automatically generate a name for the data source you are creating. -
Click Create source.
As a result, the new source will appear in the list of data sources. Now you can select this data source when creating a scan.
Creating a data source for Yandex 360
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Data Security Posture Management and go to the Data sources tab. -
In the top-right corner, click Create source.
-
Select Yandex 360.
-
Click Configure connection and configure integration with the Yandex 360 organization:
-
Specify the Organization 360
ID.You can look up the ID in your company profile
in the organization administrator account. -
Enter the OAuth token
. -
Optionally, to provide access to custom resources, e.g., to scan custom disks, create
a service application and specify the following properties:- ClientID
- Client secret
Note
This feature is not available for the Yandex 360 Minimum plan
. -
Click Save.
-
-
Add the resources you want to scan to the data source:
- To add shared disks to your organization, under Organization resources, click Add resources. Select or deselect disks as appropriate in one or more folders.
- To add custom disks to the data source, in the Custom resources section, click Add resources. Select or deselect custom disks as appropriate.
- To add all available disks to the data source, click All disks under Shared resources or Custom resources. The scan will include not only the disks existing in the selected organization when the data source is created, but also disks added later (by the time of the scan).
-
Under Include in selection, specify one or more scan scopes:
-
All files: To scan all files saved in the buckets. -
DOC/TXT: To scan.doc,.docx, and.txttext files. -
XLS/CSV: To scan.xls,.xlsx, and.csvspreadsheet files. -
PPT: To scan.pptand.pptxpresentation files. -
PDF: To scan.pdfdocument files. -
HTML/XML: To scan.htmland.xmlfiles. -
Images: To scan.jpg,.jpeg,.png,.gif,.webp, and.svgimage files. -
Custom filter: To scan all files whose names do or do not match the specified patterns:- File name contains: To scan files whose names match the specified pattern.
- File name does not contain: To ignore files whose names match the specified pattern.
Specify the patterns using the RE2
regular expression syntax. You can specify patterns in both fields, in which case the scan will use theANDlogic to select files.
You can select multiple filters at the same time; the system will use the
ORlogic to apply them. -
-
If you want to add resources with different scan scope selection settings to the same data source, click Add resources and repeat steps
6and7in the section that appears.You can add any number of resource groups to a single data source for scanning.
-
Under Information about source, indicate the data source name you will use to select this source when creating a scan. Follow these naming requirements:
- It must be from 2 to 63 characters long.
- It can only contain lowercase Latin letters, numbers, and hyphens.
- It must start with a letter and cannot end with a hyphen.
Click
on the right side of the Name field to automatically generate a name for the data source you are creating. -
Click Create source.
As a result, the new source will appear in the list of data sources. Now you can select this data source when creating a scan.