Configuring a Data Storage Policy
This section describes how to configure a security baseline policy for data storage. By default, the General Data Protection type is used, and data is classified into levels L1 through L4. You can change data protection requirements (Suggestion, Not required, or Required). You can also click Configure Data Protection Type to deselect built-in protection types and select custom ones.
- Data categorization and leveling: Classify and grade data stored at rest, and apply security policies and assurance measures based on the data security levels.
- Storage isolation: Store data of different levels separately, and use physical or logical isolation mechanisms to control data flow between regions.
- Integrity: Ensure data integrity using measures such as cryptographic technologies and integrity monitoring.
- Reliability: Use active/standby or cluster deployment to ensure high availability of stored data.
- Security control: Use primary/standby or cluster deployment to ensure high availability of stored data.
- Backup and restoration: Establish a data backup and restoration mechanism and develop a data DR emergency plan to detect and restore data immediately in case of data loss or damage.
- Encryption: Use data encryption and disk encryption to ensure storage confidentiality.
Notes and Constraints
- Deselected built-in measures will not be displayed in the baseline policy table.
- If you deselect a built-in data protection type, it will not be displayed in the baseline policy list, and its default policy requirements will be cleared. The next time you select the type, you will need to configure its policy requirements.
Configuring Data Storage Security Measures
- Log in to the DSC console.
- Click
in the upper left corner and select a region or project. - In the navigation pane on the left, choose .
- Click the Storage tab.
- Click Configure Measures. The Configure Measure page is displayed.
- Built-in measures: DSC provides built-in measures for different data phases based on Huawei Cloud data security governance experience. For details about the built-in measures, see Built-in Measures.
- Custom Measures: The added custom measures are displayed in the baseline policy list.
- You can uncheck the box to deselect unnecessary measures. The deselected measures will not be displayed in the

policy baseline list. - Click Add. The Add Custom Protection Measure page is displayed.
- Enter the measure name and measure description. Click OK to return to the Configure Measure page, where you can see the added measure.
- Click Edit in the Operation column to modify a measure, or click Delete to delete an unnecessary measure.
- Click OK to view the configured measures in the policy baseline list.
Configuring Data Protection Types for Storage
- On the Storage tab page, click Configure Data Protection Type.
- Built-in Data Protection Type: If a protection type is deselected, the type will not appear in the baseline policy list, and the default policy requirements of this type will be cleared. You will need to customize the policy requirements for the protection type the next time.
- General Data Protection: This type of protection is applied to data that has not been classified based on sensitive data identification.
- Leveled Data Protection Type: Leveled data protection is applicable to data that has been classified and graded. DSC includes built-in sensitive data levels from L1 to L4. If this option is deselected, it will not be displayed in the policy baseline list.
- Custom Data Protection Type: The added custom data protection types are displayed in the policy baseline list.
Select a custom level from the drop-down list box. If no custom level is available, create one by referring to Adding a Sensitivity Level.
- Click OK. In the policy baseline table, view the data protection type.
Modifying Data Storage Protection Requirements
- On the Storage tab page, click Modify Protection Requirements. For example, select Not required, Suggestion, or Required from the drop-down list in the Data Categorization and Leveling column of the General Data Protection row.Figure 1 Modifying protection requirements
- Click Save Changes. You can also click Cancel Changes in the upper left corner to cancel the modification and return to the previous protection requirements.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot