Creating a DSPM scan
Data Security Posture Management scans Yandex Object Storage buckets and Yandex 360 Yandex Disks
Getting started
Before you start using the DSPM module, set up your workspace and specify the default folder to store Data Security Posture Management (DSPM) data:
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
DSPM. -
If the Security Deck settings window opens, this means the DSPM data storage folder has not been configured. Under Choose your default folder, select a folder to store the module data by default and click Save at the bottom of the page.
-
If the DSPM UI opens, this means the module's data storage folder has already been configured, so you can continue working.
You can change the DSPM data storage folder path. To do this, navigate to the Settings tab. Under Default storage, select another folder.
-
Activate DSPM in the current workspace. To do this, click
Configure DSPM at the top right.In the window that opens, navigate to the Control modules tab. Under Control modules, select the **Data Security Posture Management (DSPM)
** module and click Save.If you have no workspaces yet, create one and activate the **Data Security Posture Management (DSPM)
** when creating the workspace.
Creating a scan
When DSPM is activated, data analysis starts automatically. Based on the results of analysis for buckets, you can create a continuous update scan in Interface v2.0.
In the v1.0 Interface, you can create regular scanning for buckets and disks.
To create continuous change scanning, create a scan scope:
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
DSPM. -
On the DSPM module page, select
Interface: v2.0and navigate to the Scan scopes tab. -
Click New scan or New scan scope if you already have a scan running. The scan scope creation window will open.
-
Select the buckets, folders, or clouds you want scanned and click Add to the scan.
-
Under Resource group, specify locations requiring continuous monitoring:
- In the Resources line, specify clouds or folders:
AllorSelected. Select clouds or folders as needed. - In the Buckets line, select
All bucketsorPublic buckets. - Optionally, configure
File filter:- Add formats.
- Set maximum and minimum size limits.
- Specify a regular expression to check the path against.
Optionally, add another resource group. You can add several resource groups, each with filters of its own.
- In the Resources line, specify clouds or folders:
-
Under Data categories for search, specify the data to search in. You can select both In text and On images data. Enable
Data for searchto search for all sensitive data or select a specific data type:- In text:
Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).Financial data: Bank card details.Secrets: Cloud access keys, passwords, tokens, SSH keys, etc.
- On images:
Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).Financial data: Bank card details.Medical data: Data from medical documents and images.Other: Data from personal documents, including military IDs, pensioner IDs, academic certificates, etc.
- In text:
-
Under Scope parameters, enter a name for the scan scope in the Name field. It can describe the controlled area, include criticality, sensitive data search settings, and other useful information.
-
Click Create.
DSPM will begin continuous monitoring of changes within the scan scope for effective and targeted control of your sensitive data.
To create regular scanning, you need a data source. Create it in advance or during the scan creation.
To create regular scanning for Object Storage or Yandex 360:
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
DSPM. -
On the DSPM module page, select
Interface: v1.0and navigate to the Regular scans tab. -
In the top-right corner, click New scan.
-
Under Data sources, select the data source: an Object Storage bucket or Yandex 360
disk.If necessary, create a new data source.
Note
If access to the bucket is controlled by a policy, allow access to Security Deck IP addresses in the bucket policy settings. For a list of addresses, see Public IP address ranges.
-
If you are using a bucket as a source, under Access to data in sources, select the service account to use for scanning. If you need a new service account, click Create a new one.
Warning
To run the scan, make sure the service account is assigned the
dspm.workerrole for all buckets you want to scan. If the buckets are encrypted, your service account also needs thekms.keys.decrypterrole for the relevant Yandex Key Management Service encryption keys. -
Under Data search categories, select the data categories to scan for, separately for text and images:
- In text:
Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).Financial data: Bank card details.Secrets: Cloud access keys, passwords, tokens, SSH keys, etc.
- On images:
Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).Financial data: Bank card details.Medical data: Data from medical documents and images.Other: Data from personal documents, including military IDs, pensioner IDs, academic certificates, etc.
You can select all the available categories at once or any combination of them.
- In text:
-
Optionally, under Connecting custom dictionaries, submit a request for connection of custom dictionaries for sensitive data search:
-
Click Yes, I do.
Note
Once you select any of the options, the section will no longer be displayed.
If you have clicked No, you can change your decision. Do it by filling out this form
. -
On the page that opens, fill out the fields and click Submit.
Our team will process your request and contact you for details and to inform you of the results.
-
-
Under Scan settings:
-
Select Scan method:
- Full: Scan all source objects of the supported types. This method ensures high accurracy of sensitive data detection.
- Partial: Scan only the selected partial data. Accuracy of sensitive data detection is lower, which is good for processing large amounts of data.
-
In the Start field, select the frequency for the new scan:
Once,Every 7 days,Every 30 days,Every 90 days, or set your own frequency by selectingCustom number of days. -
In the Name of scan field, specify the name to find your new scan. Follow these naming requirements:
- Length: between 3 and 63 characters.
- It can only contain lowercase Latin letters, numbers, and hyphens.
- It must start with a letter and cannot end with a hyphen.
-
-
Click Create scan without validation.
The new scan will appear in the scan list, ready to run.