Help Center/ Data Security Center/ User Guide/ Classification and Grading/ Configuring Sensitive Data Identification Rules
Updated on 2026-07-27 GMT+08:00

Configuring Sensitive Data Identification Rules

  • Identification templates: DSC provides built-in identification templates for personal information and specific industries (for example, finance and Internet of Vehicles). For details, see Supported Built-in Identification Templates. You can use them to identify sensitive data in the assets managed by DSC. You can use DSC built-in templates or create a custom template. You can replicate a template and modify its rules, or perform the operations in Batch Importing Rules.
  • Identification rules and levels: You can use the built-in rules and levels or create new ones. They are essential for creating an identification template and classifying data.

Identification template: An identification template can contain one or more categories. A category consists of multiple identification rules and sensitivity levels.

Constraints

Type

Constraints

Creating an identification template

A maximum of 20 identification templates can be created for an account.

Deleting an identification template

  • A built-in template and the default identification template cannot be deleted.
  • Templates associated with identification tasks cannot be deleted.

Modifying a rule category

You can modify categories only for user-defined templates that are not currently referenced.

Adding a sensitivity level

A maximum of 20 sensitivity levels can be created.

Step 1: Add a Custom Rule

Sensitive data identification rules include built-in rules and user-defined rules. Users can also import rules in batches. You can select built-in or customized identification rules when creating or editing an identification template.

Ensure that there is a custom identification template available.

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane, choose Classification and Grading > Identification Configuration. The Identification Template tab page is displayed.
  4. Click the Identification Rule tab page.
  5. Click Create Rule in the upper left corner of the page.
  6. In the displayed dialog box, set required parameters based on Table 1.

    Table 1 Parameter description

    Parameter

    Description

    Basic Rule Details

    Rule Name

    You can customize a rule name.

    The rule name must:

    • Contain a maximum of 255 characters.
    • Consist of letters, digits, underscores (_), hyphens (-), and brackets.
    • Be unique.

    Description

    Enter a rule description.

    Match Condition

    Match Type

    This parameter can be set to Rule matching or Keyword matching.

    • Keyword matching indicates that the rule can be executed using keywords.
    • Regular matching is used to match (specify and identify) characters, words, and patterns.
      NOTE:

      For Hive data in MRS, sensitive data can be identified only when Match Type is Rule matching and Rule is Content > Include.

    Rule

    This parameter is displayed when Match Type is set to Rule matching. Select the rule content from the drop-down list.
    • Choose Column Name > Include, Column Comment > Include, Content > Include, Table Name > Include, or Table Comment > Include, and enter a keyword to check whether the column name/remark/content or table name/remark contains the keyword.
    • Choose Column Name > Regex, Column Remark > Regex, Content > Regex, Table Name > Regex, or Table Comment > Regex, and enter the regular expression to check whether it is matched.

      Example of a regular expression that matches positive integers: ^[1-9]\d*$

    • Choose Column Name > Not include, Column Comment > Not include, Content > Not include, Table Name > Not include, or Table Comment > Not include, and enter a keyword to check whether the table name, table comment, column name, or content does not contain the keyword.
    • Choose Content > Keyword and enter multiple keywords. The relationship between the keywords is OR, meaning if any keyword is found in the content, it will be matched.
    NOTICE:

    For Hive data in MRS, sensitive data can be identified only when Match Type is Rule matching and Rule is Content > Include.

    Logical Relationship

    If Match Type is set to Rule Matching and two or more rules are added, you need to select this parameter.
    • AND: Multiple rules must be matched at the same time.
    • OR: Only one of the rules needs to be matched.

    Test Rule

    • This parameter is displayed when Match Type is set to Rule Matching.
    • Enter the rule content and click Test. The test result of the rule is displayed in the Test Result area.
    • You can click Add to add multiple rules for test.
    • Both built-in rules and user-defined rules support rule tests. To test a built-in rule, click Details in the Operation column of the rule list. On the Edit Rule page, enter the rule for test.
      NOTE:
      • Image rules cannot be tested.
      • Rule test is not supported when Match Type is set to Keyword matching.
      • Only the first matching result of the test content is displayed.

    Content

    • This parameter is displayed when Match Type is set to Keyword Matching.
    • Multiple keywords are separated by line breaks.

    Identification Threshold Configuration

    Hits

    Applicable to unstructured data. You can select the threshold to Low, Medium, or High. A higher threshold requires more hits.

    Hit rate

    Applicable to structured data. You can drag the slider to set the value. A larger value indicates a higher hit rate.

    Exception Matching Conditions (Optional)

    Match Type, Rule, Rule Test, Content

    You can configure these parameters to further reduce false positives if the settings in the Match Condition area are insufficient.

    Configure them in the same way you configure the Match Condition parameters. For details, see the row of Match Condition.

    Add to Template (Optional)

    Template and Classification

    Select options as needed from the Template, Classification, and Classification and Grading drop-down list boxes to add the rule to templates.

    • Click Add to add the rule to multiple templates.
    • You can delete templates, but at least one template must be retained.

  7. Click OK.

Ensure that there is a custom identification template available. Identification rules can be imported in batches only for rule templates.

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane, choose Classification and Grading > Identification Configuration. The Identification Template tab page is displayed.
  4. Click the Identification Rule tab. The Identification Rule page is displayed.
  5. Click Batch Import Rules.
  6. Click Import rule templates to download the template to the local PC.

    Import requirements:

    • Only XLSX files are supported. The allowed maximum file size is 5 MB.
    • Maximum of 5,000 records per import. Records exceeding this limit cannot be imported.
    • Duplicate rules will not be imported.
    • Classifications specified in the Excel file will be automatically created if they do not exist in the target template.

  7. (Optional) Select an identification template from the drop-down list. If no template is selected, the imported rules will not be added to any template by default.
  8. Click Add file and select the template you have filled in.
  9. Click Import to import the rule to the selected identification template.
  10. You can also click Add Rule on the details page of the identification template and select Batch Import Rule to import rules in batches to the template.

    In the Operation column of the rule list, you can click Delete in the row of a rule to delete it. Alternatively, you can select one or multiple rules and click Batch Delete above the list to delete them at a time.

Step 2: Create or Disable a Level

DSC offers four built-in sensitive data levels (L1 to L4). Refer to Table 2 for their security and level definitions. If these built-in levels are insufficient, you can customize them as described in this section.

Table 2 Definition

Security

Level

Definition

Extremely high

L4

Disclosure, tampering, or illegal use of personal data at this level will have a particularly severe impact on the rights and interests of individuals and organizations. Examples: Prolonged or permanent damage to an individual's property safety, dignity, or physical/mental health; enterprise business qualification cancellation, prolonged business suspension, or risk of bankruptcy; significant harm to economic operations, social order, and public interests.

High

L3

Disclosure, tampering, or illegal use of personal data at this level will have a serious impact on the rights and interests of individuals and organizations. Examples: Individual unemployment, fraud, fund theft, or reputational damage; enterprise business qualification suspension, or significant economic, technological, or reputational loss.

Medium

L2

Disclosure, tampering, or illegal use of personal data at this level will have an adverse impact on the rights and interests of individuals and organizations. Examples: Individual psychological harm or harassment; enterprise service interruption, or minor economic, technological, or reputational damage.

Low

L1

Disclosure, tampering, or illegal use of personal data at this level will have no impact or only a minimal impact on the rights and interests of individuals and organizations. Example: Individual disturbance.

A maximum of 20 sensitivity levels can be created.

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane, choose Classification and Grading > Identification Configuration. The Identification Template tab page is displayed.
  4. Click the Sensitivity Configuration tab and click Adding a Level in the upper left corner.
  5. In the displayed dialog box, set required information based on Table 3.

    Table 3 Parameter description

    Parameter

    Description

    Level Name

    Enter a user-defined level name.

    Level Color

    You can select a color based on the sensitivity level. A higher level color value indicates a higher sensitivity.

    For example, name and gender are low-sensitivity data, and the ID card number and encryption key are high-sensitivity data.

  6. Click OK.

A built-in level cannot be disabled.

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane, choose Classification and Grading > Identification Configuration. The Identification Template tab page is displayed.
  4. Click the Sensitivity Configuration tab to view the sensitivity level configuration list.
  5. Locate the target level to be disabled, click Disable in the Operation column.

    • Disabled levels are not displayed when you create or edit a template.
    • To enable a level, click Enabled in the Operation column of the row that contains the level.

Step 3: Add and Edit an Identification Template

DSC provides a built-in template by default. You can create or copy a template to customize the settings. You can edit identification templates to view, add, and modify rules.

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane, choose Classification and Grading > Identification Configuration. The Identification Template tab page is displayed.
  4. Click Create Template in the upper left corner of the page. In the Create Template dialog box, set parameters according to Table 4.

    Table 4 Parameters for creating a template

    Parameter

    Description

    Name

    Only English letters, numbers, hyphens (-), and underscores (_) are allowed.

    Template Type

    Select the type of the new template. It determines whether the template will be used for rule matching or model inference.

    • Rule template: A traditional identification template based on the rule matching engine. After creating this template, you need to create or import identification rules before using it for sensitive data identification. The rules can be imported in batches. For details, see Batch Importing Rules. After the template is created, the Custom label will be displayed on its card.
    • Large language model template: A template used for model inference and not dependent on specific rules. You only need to briefly describe your data classification requirements before using the template for sensitive data identification. Classifications can be imported in batches. For details, see Batch Importing Classifications. After the template is created, the Large model label will be displayed on its card.

    Import Built-in Rules

    This parameter is displayed if Template Type is set to Rule template.

    You can select whether to automatically import system built-in rules to the template. If you only want to use custom or imported rules, select No.

    • Yes: Import built-in rules.
    • No: Create an empty template.

    Description (Optional)

    Enter the description of the template.

  5. Click OK. The new identification template is displayed in the identification template list.
  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane, choose Classification and Grading > Identification Configuration. The Identification Template tab page is displayed.
  4. Locate the target template, Click Copy. In the displayed Copy Template dialog box, enter the new template name and description.
  5. Click OK.

You can edit, create, and import rules in a custom template. You can also export certain templates to OBS.

For built-in templates, you can only change the status of existing rules. For custom templates that are not referenced, you can edit and modify rules and categories.

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane, choose Classification and Grading > Identification Configuration. The Identification Template tab page is displayed.
  4. Locate the target template, click Details. The template details page is displayed.

    • Adding a category: Click the next to All or a category name.
    • Editing a category: Click the next to a category name.
    • Deleting a category: Click the next to a category name.
    • Importing categories in batches: For details, see Batch Importing Classifications.
    • Creating a rule: For details, see Creating a Custom Rule.
    • Importing rules in batches: For details, see Batch Importing Rules.
    • Managing the rules under a category: In the navigation tree on the left, select a category name. In the category list on the right, click the next to the category name to expand all rules under the category.
      • Adding a rule: Click Add Rule in the Operation column of a category. On the Add Rule page that is displayed, select a rule from the drop-down list and click OK. For details about how to add a custom rule, see Creating a Custom Rule. You can also click Batch Import Rules to import multiple rules at a time. For details, see Batch Importing Rules.
      • Changing a category: Select a rule and click Change Category in the upper left corner of the rule list. In the displayed dialog box, select a category and click OK. You can modify categories only for user-defined templates that are not currently referenced.
      • Batch deleting rules: Select rules and click Delete Rules in the upper left corner of the rule list. In the displayed dialog box, confirm the selected rules and click OK. You can delete rules only in user-defined templates that are not referenced.
      • Deleting a rule: Click Remove in the Operation column of a rule. In the displayed dialog box, confirm the rule information and click OK.
      • Viewing details: Click Details in the Operation column of a rule. On the Rule Details page, you can check rule details, configure Rule Content and test it, or add the rule to templates.
      • Enabling or disabling a rule: Click in the Status column to enable or disable a rule. After the rule is disabled, it will not be applied when the template is used for identification.

Only rule templates can be exported to OBS buckets and then downloaded to the local PC.

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane, choose Classification and Grading > Identification Configuration. The Identification Template tab page is displayed.
  4. Click Details of the template to be exported. The Template Hierarchy and Classification page is displayed.
  5. Click Export Template to OBS above the rule list.
  6. In the Export Template to OBS dialog box, select a value from the Export Target Bucket drop-down list.
  7. Click OK. The status of Export Template to OBS changes to Queuing or Running.
  8. Refresh the page. Click Download Result File from OBS Bucket when the button is available. In the dialog box that is displayed, view the file path and click OK to go to OBS to download the result file.

After creating an empty template, you can batch import local categories.

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane, choose Classification and Grading > Identification Configuration. The Identification Template tab page is displayed.
  4. Click Details of the Large model template. The Template Hierarchy and Classification page is displayed.
  5. Click Batch Import Classification above the category list.
  6. In the Batch Import Classification dialog box, click Download Template to download the template, sort out the categories according to the template, and click Add file to upload the template.

    Requirements for importing files:
    • Maximum of 400 records per import; exceeding this limit will prevent import.
    • Duplicate data will be ignored during import.
    • Files must be in XLSX format and not exceed 2,000 KB.

  7. After the upload is successful, click OK. The import is successful.

Related Operations

  • Click Set as Default to set the template as the default template. The default template is the built-in identification template.
  • Click Overview to view the template type and level.
  • Click Details to add rules or modify categories. For built-in templates, you can only change the status of existing rules.
  • Click Delete in the Operation column of the row that contains the classification and grading template to be deleted, and click OK to delete the template. The classification and grading template in use cannot be deleted. Delete the corresponding identification task first and then delete the classification and grading template. A built-in template and the default identification template cannot be deleted.
  • In the Identification Rule tab, locate the target rule and click Edit in the Operation column to view and modify the rule. For built-in rules, only Add to Template and Test Rule can be modified.
  • In the Sensitivity Configuration tab, locate the target level and click Edit in the Operation column to modify the level content. Built-in levels cannot be edited.
  • In the Sensitivity Configuration tab, locate the target level and click Delete in the Operation to delete the level. Only custom levels that are not referenced can be deleted.