Sensitive data search in Object Storage
Note
This feature is at the Preview stage.
Sensitive data search is a tool powered by Data Security Posture Management that helps you detect sensitive information stored in Object Storage buckets for timely action to protect it through access policies, anonymization, etc.
You can create bucket scanning tasks and manage scan results via the Object Storage interface in the management console
Sensitive data search is subject to the DSPM pricing policy.
Scanning a bucket
Scanning discovers sensitive information within a bucket. To initiate scanning, use a service account.
Data categories
When creating a scan, you can specify which data categories to search for. You can target all available categories at once or select specific categories.
Data categories available for scanning:
Personal data: Full names, email addresses, phone numbers, and social security numbers (SNILS).Financial data: Bank card details.Secrets: Cloud access keys, passwords, tokens, SSH keys, etc.
Scan results
After a scan is complete, the system displays its results available for you to view, download, or export.
If an error occur during scanning, you can view diagnostic messages describing the issue under Messages and errors. For more information about errors, see Object Storage quotas and limits.
Centralized Data Security Posture Management
The Object Storage UI supports sensitive data search in individual buckets. To monitor data in multiple buckets at the folder, cloud, or organization level, use the DSPM module inside Yandex Security Deck. With DSPM, you can aggregate multiple buckets, folders, and clouds into a single data source and set up scheduled scans.