Yandex Cloud
Search
Contact UsGet started
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • AI for business
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
© 2025 Direct Cursus Technology L.L.C.
Yandex Security Deck
    • All guides
      • Creating a data source
      • Creating a scan
    • Kubernetes® Security Posture Management (KSPM)
  • Pricing policy
  1. Step-by-step guides
  2. Data Security Posture Management (DSPM)
  3. Creating a scan

Creating a DSPM scan

Written by
Yandex Cloud
Improved by
Danila N.
Updated at August 14, 2025

Note

This feature is in the Preview stage. To get access, contact tech support or your account manager.

Data Security Posture Management (DSPM) scans data sources to identify sensitive information in buckets.

Before you start using DSPM, set up the default folder to store Security Deck data.

To create a scan:

Security Deck UI
  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select DSPM and go to the Regular scans tab.

  3. In the top-right corner, click New scan.

  4. Under Data sources, select the data source you need.

    If necessary, create a new data source.

  5. Under Access to data in sources, select the service account to use to run your scans. If you need to create a new service account, click Create new.

    Warning

    To run the scan, make sure the service account is assigned the dspm.worker role for all buckets you want to scan. If the buckets are encrypted, your service account also needs the kms.keys.decrypter role for the relevant Yandex Key Management Service encryption keys.

  6. Under Data search categories, select the data categories to scan for:

    • Financial data: Credit or debit card details.
    • Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).
    • Secrets: Cloud access keys, passwords, tokens, SSH keys, etc.

    You can select all the available categories at once or any combination of them.

  7. Under Scan settings:

    1. In the Start field, select the new scan frequency: Once, Every 7 days, Every 30 days, Every 90 days, or set a custom frequency by selecting Custom number of days.

    2. In the Scan name field, specify the name to identify your new scan. Follow these naming requirements:

      • It must be from 2 to 63 characters long.
      • It can only contain lowercase Latin letters, numbers, and hyphens.
      • It must start with a letter and cannot end with a hyphen.
  8. Click Create scan.

The new scan will appear in the scan list, ready to run.

See alsoSee also

  • Creating a DSPM data source
  • Data Security Posture Management (DSPM)
  • Common Yandex Security Deck roles

Was the article helpful?

Previous
Creating a data source
Next
Kubernetes® Security Posture Management (KSPM)
© 2025 Direct Cursus Technology L.L.C.