Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Security Deck
    • All guides
      • Overview
      • Managing data analysis
      • Preparing data for scanning
      • Creating a scan
      • Managing scan results
  • Pricing policy
  • Audit Trails events
  • Release notes

In this article:

  • Getting started
  • Creating a scan
  1. Step-by-step guides
  2. Data Security Posture Management (DSPM)
  3. Creating a scan

Creating a DSPM scan

Written by
Yandex Cloud
Improved by
Danila N.
Updated at July 29, 2026
View in Markdown
  • Getting started
  • Creating a scan

Data Security Posture Management scans Yandex Object Storage buckets and Yandex 360 Yandex Disks for sensitive information in storage.

Getting startedGetting started

Before you start using the DSPM module, set up your workspace and specify the default folder to store Data Security Posture Management (DSPM) data:

Security Deck UI
  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select DSPM.

  3. If the Security Deck settings window opens, this means the DSPM data storage folder has not been configured. Under Choose your default folder, select a folder to store the module data by default and click Save at the bottom of the page.

  4. If the DSPM UI opens, this means the module's data storage folder has already been configured, so you can continue working.

    You can change the DSPM data storage folder path. To do this, navigate to the Settings tab. Under Default storage, select another folder.

  5. Activate DSPM in the current workspace. To do this, click Configure DSPM at the top right.

    In the window that opens, navigate to the Control modules tab. Under Control modules, select the **Data Security Posture Management (DSPM)
    ** module and click Save.

    If you have no workspaces yet, create one and activate the **Data Security Posture Management (DSPM)
    ** when creating the workspace.

Creating a scanCreating a scan

When DSPM is activated, data analysis starts automatically. Based on the results of analysis for buckets, you can create a continuous update scan in Interface v2.0.

In the v1.0 Interface, you can create regular scanning for buckets and disks.

Interface v2.0
Interface v1.0

To create continuous change scanning, create a scan scope:

  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select  DSPM.

  3. On the DSPM module page, select Interface: v2.0 and navigate to the Scan scopes tab.

  4. Click New scan or New scan scope if you already have a scan running. The scan scope creation window will open.

  5. Select the buckets, folders, or clouds you want scanned and click Add to the scan.

  6. Under Resource group, specify locations requiring continuous monitoring:

    1. In the Resources line, specify clouds or folders: All or Selected. Select clouds or folders as needed.
    2. In the Buckets line, select All buckets or Public buckets.
    3. Optionally, configure File filter:
      • Add formats.
      • Set maximum and minimum size limits.
      • Specify a regular expression to check the path against.
        Optionally, add another resource group. You can add several resource groups, each with filters of its own.
  7. Under Data categories for search, specify the data to search in. You can select both In text and On images data. Enable Data for search to search for all sensitive data or select a specific data type:

    • In text:
      • Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).
      • Financial data: Bank card details.
      • Secrets: Cloud access keys, passwords, tokens, SSH keys, etc.
    • On images:
      • Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).
      • Financial data: Bank card details.
      • Medical data: Data from medical documents and images.
      • Other: Data from personal documents, including military IDs, pensioner IDs, academic certificates, etc.
  8. Under Scope parameters, enter a name for the scan scope in the Name field. It can describe the controlled area, include criticality, sensitive data search settings, and other useful information.

  9. Click Create.

DSPM will begin continuous monitoring of changes within the scan scope for effective and targeted control of your sensitive data.

To create regular scanning, you need a data source. Create it in advance or during the scan creation.

To create regular scanning for Object Storage or Yandex 360:

  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select DSPM.

  3. On the DSPM module page, select Interface: v1.0 and navigate to the Regular scans tab.

  4. In the top-right corner, click New scan.

  5. Under Data sources, select the data source: an Object Storage bucket or Yandex 360 disk.

    If necessary, create a new data source.

    Note

    If access to the bucket is controlled by a policy, allow access to Security Deck IP addresses in the bucket policy settings. For a list of addresses, see Public IP address ranges.

  6. If you are using a bucket as a source, under Access to data in sources, select the service account to use for scanning. If you need a new service account, click Create a new one.

    Warning

    To run the scan, make sure the service account is assigned the dspm.worker role for all buckets you want to scan. If the buckets are encrypted, your service account also needs the kms.keys.decrypter role for the relevant Yandex Key Management Service encryption keys.

  7. Under Data search categories, select the data categories to scan for, separately for text and images:

    • In text:
      • Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).
      • Financial data: Bank card details.
      • Secrets: Cloud access keys, passwords, tokens, SSH keys, etc.
    • On images:
      • Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).
      • Financial data: Bank card details.
      • Medical data: Data from medical documents and images.
      • Other: Data from personal documents, including military IDs, pensioner IDs, academic certificates, etc.

    You can select all the available categories at once or any combination of them.

  8. Optionally, under Connecting custom dictionaries, submit a request for connection of custom dictionaries for sensitive data search:

    1. Click Yes, I do.

      Note

      Once you select any of the options, the section will no longer be displayed.

      If you have clicked No, you can change your decision. Do it by filling out this form.

    2. On the page that opens, fill out the fields and click Submit.

      Our team will process your request and contact you for details and to inform you of the results.

  9. Under Scan settings:

    1. Select Scan method:

      • Full: Scan all source objects of the supported types. This method ensures high accurracy of sensitive data detection.
      • Partial: Scan only the selected partial data. Accuracy of sensitive data detection is lower, which is good for processing large amounts of data.
    2. In the Start field, select the frequency for the new scan: Once, Every 7 days, Every 30 days, Every 90 days, or set your own frequency by selecting Custom number of days.

    3. In the Name of scan field, specify the name to find your new scan. Follow these naming requirements:

      • Length: between 3 and 63 characters.
      • It can only contain lowercase Latin letters, numbers, and hyphens.
      • It must start with a letter and cannot end with a hyphen.
  10. Click Create scan without validation.

The new scan will appear in the scan list, ready to run.

Useful linksUseful links

  • Data Security Posture Management (DSPM)
  • Common Yandex Security Deck roles

Was the article helpful?

Previous
Preparing data for scanning
Next
Managing scan results
© 2026 Direct Cursus Technology L.L.C.