Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Security Deck
    • All guides
      • Overview
      • Managing data analysis
      • Preparing data for scanning
      • Creating a scan
      • Managing scan results
  • Pricing policy
  • Audit Trails events
  • Release notes

In this article:

  • Getting started
  • Creating a scan scope or data source
  1. Step-by-step guides
  2. Data Security Posture Management (DSPM)
  3. Preparing data for scanning

Preparing data for scanning in DSPM

Written by
Yandex Cloud
Improved by
Danila N.
Updated at July 23, 2026
View in Markdown
  • Getting started
  • Creating a scan scope or data source

To start a continuous update scan, create a scope in Interface v2.0.

Before creating a regular scan in DSPM, prepare a data source in Interface v1.0. You can also do this when creating a scan.

Getting startedGetting started

Before you start using the DSPM module, set up your workspace and specify the default folder to store Data Security Posture Management (DSPM) data:

Security Deck UI
  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select DSPM.

  3. If the Security Deck settings window opens, this means the DSPM data storage folder has not been configured. Under Choose your default folder, select a folder to store the module data by default and click Save at the bottom of the page.

  4. If the DSPM UI opens, this means the module's data storage folder has already been configured, so you can continue working.

    You can change the DSPM data storage folder path. To do this, navigate to the Settings tab. Under Default storage, select another folder.

  5. Activate DSPM in the current workspace. To do this, click Configure DSPM at the top right.

    In the window that opens, navigate to the Control modules tab. Under Control modules, select the **Data Security Posture Management (DSPM)
    ** module and click Save.

    If you have no workspaces yet, create one and activate the **Data Security Posture Management (DSPM)
    ** when creating the workspace.

Creating a scan scope or data sourceCreating a scan scope or data source

Interface v2.0
Interface v1.0

Enabling Data Security Posture Management automatically starts data analysis in Yandex Object Storage buckets. After data analysis detects potentially dangerous resources, you can create a scan scope for them:

  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select  DSPM.

  3. On the DSPM module page, select Interface: v2.0 and navigate to the Scan scopes tab.

  4. Click New scan or New scan scope if you already have a scan running. The scan scope creation window will open.

  5. Select the buckets, folders, or clouds you want scanned and click Add to the scan.

  6. Under Resource group, specify locations requiring continuous monitoring:

    1. In the Resources line, specify clouds or folders: All or Selected. Select clouds or folders as needed.
    2. In the Buckets line, select All buckets or Public buckets.
    3. Optionally, configure File filter:
      • Add formats.
      • Set maximum and minimum size limits.
      • Specify a regular expression to check the path against.
        Optionally, add another resource group. You can add several resource groups, each with filters of its own.
  7. Under Data categories for search, specify the data to search in. You can select both In text and On images data. Enable Data for search to search for all sensitive data or select a specific data type:

    • In text:
      • Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).
      • Financial data: Bank card details.
      • Secrets: Cloud access keys, passwords, tokens, SSH keys, etc.
    • On images:
      • Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).
      • Financial data: Bank card details.
      • Medical data: Data from medical documents and images.
      • Other: Data from personal documents, including military IDs, pensioner IDs, academic certificates, etc.
  8. Under Scope parameters, enter a name for the scan scope in the Name field. It can describe the controlled area, include criticality, sensitive data search settings, and other useful information.

  9. Click Create.

DSPM will begin continuous monitoring of changes within the scan scope for effective and targeted control of your sensitive data.

A data source contains information about the storages to scan and additional settings. The available storages are Yandex Object Storage buckets and disks in Yandex 360. You cannot use both Object Storage and Yandex 360 storage in the same data source.

To create a data source for Object Storage and Yandex 360:

  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select DSPM.

  3. On the DSPM** page, select Interface: v1.0 and navigate to the Data sources tab.

  4. In the top-right corner, click Create source and select  Object Storage or  Yandex 360.

    Object Storage
    Yandex 360

    Add the resources you want to scan to the data source:

    • To add individual buckets, click Select bucket and select one or more buckets from available folders.

      You can filter buckets by access settings (Restricted or Public) and by bucket name as needed.

    • To add clouds or folders to your data source, click Select cloud or catalog and select all or some of the available clouds and/or folders.

      After you select clouds and folders under Include in scan, select the buckets to scan:

      • All buckets
        The data source will include all buckets in the selected clouds and folders. In which case the scan will cover not only the buckets existing at the time you create the data source but also those you add to these clouds and folders by the time you run the scan in the future.
      • Public buckets
        The data source will include buckets with public access configured. Only these buckets will be scanned for personal data. Disable public access for these buckets to automatically remove them from the scan.
    1. Click Configure connection and configure integration with the Yandex 360 organization:

      1. Specify the Organization 360 ID.

        You can look up the ID in your company profile in the organization administrator account.

      2. Enter the OAuth token.

      3. Optionally, to provide access to custom resources, e.g., to scan custom disks, create a service application and specify the following properties:

        • ClientID
        • Client secret

        Note

        This feature is not available for the Yandex 360 Minimum plan.

      4. Click Save.

    2. Add the resources you want to scan to the data source:

      • To add shared disks to your organization, under Organization resources, click Add resources. Select or deselect disks as appropriate in one or more folders.
      • To add custom disks to the data source, click Add resources under User resources. Select or deselect custom disks as appropriate.
      • To add all available disks to the data source, click All disks under Organization resources or User resources. The scan will include not only the disks existing in the selected organization when the data source is created, but also disks added later (by the time of the scan).
  5. Under Include in selection, specify one or more scan scopes:

    • All files: To scan all files saved in the buckets.

    • DOC / TXT: To scan .doc, .docx, and .txt text files.

    • XLS / CSV: To scan .xls, .xlsx, and .csv spreadsheet files.

    • PPT: To scan .ppt and .pptx presentation files.

    • PDF: To scan .pdf document files.

    • HTML / XML: To scan .html and .xml files.

    • Images: To scan .jpg, .jpeg, .png, .gif, .webp, and .svg image files.

    • Custom filter: To scan all files whose names do or do not match the specified patterns:

      • The file name contains: To scan files whose names match the specified pattern.
      • The file name does not contain: To ignore files whose names match the specified pattern.

      Specify the patterns using the RE2 regular expression syntax. You can specify patterns in both fields, in which case the scan will use the AND logic to select files.

    You can select multiple filters at the same time; the system will use the OR logic to apply them.

  6. If you want to add resources with different scan scope selection settings to the same data source, click Add a resource group and repeat steps 6 and 7 in the section that appears.

    You can add any number of resource groups to a single data source for scanning.

  7. Under Information about source, indicate the data source name you will use to select this source when creating a scan. Follow these naming requirements:

    • Length: between 3 and 63 characters.
    • It can only contain lowercase Latin letters, numbers, and hyphens.
    • It must start with a letter and cannot end with a hyphen.

    Click on the right side of the Name field to automatically generate a name for the data source you are creating.

  8. Click Create source.

As a result, the new source will appear in the list of data sources. Now you can select this data source when creating a scan.

Useful linksUseful links

  • Creating a DSPM scan
  • Data Security Posture Management (DSPM)
  • Common Yandex Security Deck roles

Was the article helpful?

Previous
Managing data analysis
Next
Creating a scan
© 2026 Direct Cursus Technology L.L.C.