All Documents
Data Security CenterData Security Center
- What's New
- Function Overview
- Service Overview
- Getting Started
-
User Guide
- Service Provisioning
- Assets
- Overview
- Sensitive Data Identification
- Data Usage Audit
- Data Masking
- Data Watermarking
- Alarm Notifications
- Permissions Management
- Key DSC Operations
- Change History
- Best Practices
- API Reference
- SDK Reference
-
FAQs
- Product Consulting
- Regions and AZs
- Adding Data Assets
-
Sensitive Data Identification and Masking
- What Services Can Use DSC to Scan for Sensitive Data?
- How Long Does It Take for DSC to Identify and Mask Sensitive Data?
- Which Types of Sensitive Data Can Be Identified by DSC?
- Does Data Masking Affect My Raw Data?
- Does DSC Have Specific Requirements on the Character Set for Which Sensitive Data Is to Be Identified and Masked?
- How Do I Add Multiple Identification Rule Groups?
- Data Watermarking
- Data Usage Audit
- Billing, Renewal, and Repurchase After Unsubscription
- Change History
- Videos
Agency Policies Obtained After the Access To Assets Is Allowed
After the access to cloud resources is allowed, DSC can access your private OBS buckets, databases, big data assets, and data security overview. Table 1 describes the agency policies obtained after the access is allowed.
Asset |
Policy |
Scope |
Remarks |
---|---|---|---|
OBS |
OBS Adminstrator |
Global |
Used to configure OBS logs, obtain the OBS bucket list, and download items form OBS. |
EVS ReadOnlyAccess |
Regional |
Used to obtain the EVS disk list. |
|
OBS Adminstrator |
Global |
Used to obtain the logs delivered by OBS. |
|
Database |
ECS ReadOnlyAccess |
Regional |
Used to obtain the list of ECSs where databases are built. |
RDS ReadOnlyAccess |
Regional |
Used to obtain the RDS database list and related information. |
|
DWS ReadOnlyAccess |
Regional |
Used to obtain the DWS instance list. |
|
VPC FullAccess |
Regional |
Used to establish network connection and create VPC ports and security group rules |
|
KMS CMKFullAccess |
Regional |
Used to perform encryption using KMS in data masking. |
|
Big Data |
ECS ReadOnlyAccess |
Regional |
Used to obtain the list of ECSs where big data sources reside. |
CSS ReadOnlyAccess |
Regional |
Used to obtain the CSS data cluster list and data indexes. |
|
DLI Service User |
Regional |
Used to obtain the DLI queue and database. |
|
VPC FullAccess |
Regional |
Used to establish network connection and create VPC ports and security group rules. |
|
KMS CMKFullAccess |
Regional |
Used to perform encryption using KMS in data masking. |
|
Overview |
Tenant Guest |
Regional |
Used to obtain the list of cloud services used for data storage and processing. |
OBS Adminstrator |
Global |
Used to configure OBS logs, obtain the OBS bucket list, and download items form OBS. |
|
EVS ReadOnlyAccess |
Regional |
Used to obtain the EVS disk list. |
|
OBS Adminstrator |
Global |
Used for OBS to deliver logs. |
Adding Data Assets FAQs
more