Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Security Deck
    • All guides
      • Overview
      • Managing data analysis
      • Preparing data for scanning
      • Creating a scan
      • Managing scan results
  • Pricing policy
  • Audit Trails events
  • Release notes

In this article:

  • Getting started
  • Viewing analysis results
  • Saving analysis results
  1. Step-by-step guides
  2. Data Security Posture Management (DSPM)
  3. Managing data analysis

Managing DSPM data analysis

Written by
Yandex Cloud
Updated at July 23, 2026
View in Markdown
  • Getting started
  • Viewing analysis results
  • Saving analysis results

Note

Data analysis is billed separately from data source scans.

Data analysis is the first stage of DSPM Data management. The module finds, identifies, and catalogs all Object Storage buckets within a selected workspace.

The analysis starts automatically after you enable Data Security Posture Management.

Getting startedGetting started

Before you start using the DSPM module, set up your workspace and specify the default folder to store Data Security Posture Management (DSPM) data:

Security Deck UI
  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select DSPM.

  3. If the Security Deck settings window opens, this means the DSPM data storage folder has not been configured. Under Choose your default folder, select a folder to store the module data by default and click Save at the bottom of the page.

  4. If the DSPM UI opens, this means the module's data storage folder has already been configured, so you can continue working.

    You can change the DSPM data storage folder path. To do this, navigate to the Settings tab. Under Default storage, select another folder.

  5. Activate DSPM in the current workspace. To do this, click Configure DSPM at the top right.

    In the window that opens, navigate to the Control modules tab. Under Control modules, select the **Data Security Posture Management (DSPM)
    ** module and click Save.

    If you have no workspaces yet, create one and activate the **Data Security Posture Management (DSPM)
    ** when creating the workspace.

Viewing analysis resultsViewing analysis results

The summary for preliminary analysis of resources in the environment is available in Interface 2.0 in the Data analytics section of the DSPM module. To see it, do the following:

Interface v2.0
  1. In the left-hand panel, select DSPM.

  2. On the DSPM page, select Interface: v2.0 and navigate to the Data analytics tab.

    The page displays information about the number and total size of files found in the environment's resources that may potentially contain sensitive data:

    • A list of clouds, folders, and buckets that host objects potentially containing sensitive information.

      The number of files found and their total size are indicated for each cloud, folder, and bucket.

    • Infographics showing the number of files found by type and their size as a percentage.

      Click Details to expand the diagram and show more detailed information.

  3. If required, use filters to get specific information about resources and the types of files found in them:

    • Optionally, under Resource, select the resources you want analyzed.

      If needed, use the Search by resource name filter to view resources by cloud, folder, or bucket name.

    • Optionally, under Buckets, select Public for the analysis to only display information about objects located in buckets with public access.

    • Optionally, under Formats, select the MIME types of files you want analyzed:

      • Scannable: Files of all supported MIME types.
      • Documents:
        • Text documents: Text files of MIME types such as text/plain, application/rtf, etc.
        • Text processor documents: Text files of MIME types such as application/macwriteii, application/msword, etc.
        • PDF and other documents for printing: Files of MIME types such as application/pdf, image/vnd.djvu, etc.
        • Presentations: Presentation files of MIME types such as application/vnd.apple.keynote, application/vnd.ms-powerpoint, etc.
        • E-books: Text files of MIME types such as application/epub+zip, application/hwp+zip, etc.
      • Graphics and design:
        • Raster graphics: Image files of MIME types such as image/bmp, image/gif, etc.
        • Vector graphics: Image files of MIME types such as application/coreldraw, image/cgm, etc.
        • 3D models: Image files of MIME types such as image/x-3ds, model/e57, etc.
      • Multimedia:
        • Audio files: Audio files of MIME types such as audio/32kadpcm, audio/3gpp, etc.
        • Video files: Video files of MIME types such as application/mp4, application/mpeg4-generic, etc.
      • Code and service files:
        • Source code: Code files of types such as application/sieve, application/x-bat, etc.
        • Configuration files: Configuration files of MIME types such as text/x-config, text/x-ini, etc.
        • Certificates and keys: Secret files of MIME types such as application/pgp-encrypted, application/pgp-keys, etc.
        • Executables and binaries: Service files of MIME types such as application/applefile, application/java-vm, etc.
      • Datasets:
        • Structured data: Data files of MIME types such as application/cbor, application/json, etc.
        • Table formats: Table files of MIME types such as application/vnd.apple.numbers, application/vnd.ms-excel, etc.
        • Database files: Database files of MIME types such as application/vnd.lotus-approach, application/vnd.oasis.opendocument.base, etc.
        • GIS: Files of MIME types such as application/vnd.google-earth.kml+xml, application/vnd.google-earth.kmz, etc.
      • Archives and containers:
        • Archives: Archive files of MIME types such as application/gzip, application/java-archive, etc.
        • Disk images: Image files of MIME types such as application/vnd.msa-disk-image, application/x-apple-diskimage, etc.
      • Digital communications:
        • Web: Web files of MIME types such as application/ecmascript, text/html, etc.
        • Mail and messages: Files of MIME types such as application/activemessage, message/cpim, etc.
        • Fonts: Font files of MIME types such as application/font-tdpfr, application/x-font-bdf, etc.
      • Niche formats:
        • Scientific data: Scientific data files of MIME types such as application/cellml+xml, chemical/x-cdx, etc.
      • Medical images: Files of MIME types such as application/dicom.
      • Miscellaneous: Other MIME type files.

    To reset the applied filters, click Reset.

After data analysis detects potentially dangerous resources, click Add to the scan to create a continuous update scan for them.

Saving analysis resultsSaving analysis results

To save a summary for preliminary analysis of environment resources to a file or bucket:

Interface v2.0
  1. In the left-hand panel, select DSPM.

  2. On the DSPM page, select Interface: v2.0 and navigate to the Data analytics tab.

  3. Click Export and select:

    • Download results by file to save the analysis results to a local file.

      In the window that opens, click Download.

      Note

      You can save no more than 10,000 log lines to a local file. To export a larger number of lines, export the analysis results to a bucket.

    • Export results to bucket to save the analysis results to an Object Storage bucket. In the window that opens:

      • In the Bucket field, select the bucket to save the results to.

      • In the Path to bucket field, set the prefix of the object to save the results to.

      • In the File name field, specify the name of the file to save the results to. The file will automatically get the .csv extension.

      • In the Service account field, select the service account on whose behalf export will be done. You must have the right to use the selected service account, i.e., the iam.serviceAccounts.user role or higher, and the service account must have the following roles:

        • storage.uploader for the selected bucket.
        • kms.keys.encrypter for the encryption key if the bucket is encrypted.
      • Click Export to export the analysis results to the bucket.

        If the selected service account does not have enough permissions for the operation, the information about this will be displayed on the Parameter validation tab.

        Expand the section with information about missing roles, select the service account, and click Assign roles to grant the lacking permissions to this service account. Then click Export again.

Useful linksUseful links

  • Data Security Posture Management (DSPM)
  • Security Deck workspaces
  • Preparing data for scanning in DSPM
  • Creating a DSPM scan

Was the article helpful?

Previous
Overview
Next
Preparing data for scanning
© 2026 Direct Cursus Technology L.L.C.