Updated on 2026-07-27 GMT+08:00

Configuring a Data Usage Policy

This section describes how to configure a security baseline policy for data usage. By default, the General Data Protection type is used, and data is classified into levels L1 through L4. You can change data protection requirements (Suggestion, Not required, or Required). You can also click Configure Data Protection Type to deselect built-in protection types and select custom ones.

By default, General Data Protection supports the following data usage protection measures. You can click Configure Measures to deselect built-in protection measures and add custom ones. Deselected measures will not be displayed in the baseline policy list.
  • Identity authentication and access control: Authenticate users and assign permissions to identities or roles to prevent unauthorized data access.
  • Audit: Retain operation logs during data access for real-time or post-event audit.
  • Review and secondary authorization: Establish a mechanism for access permission request, review, and approval. Require verification for operations and applications. Establish a multi-factor authentication or secondary authorization mechanism.
  • Masking: Take measures such as masking and anonymization during data access, display, processing, development, and testing to prevent sensitive information leaks.
  • Blocking: Use database firewalls or take other measures to monitor and block malicious attacks, including SQL injections and vulnerability exploits, in real-time.
  • Public network protection: Prohibit external query and download channels, such as the Internet.

Notes and Constraints

  • Deselected built-in measures will not be displayed in the baseline policy table.
  • If you deselect a built-in data protection type, it will not be displayed in the baseline policy list, and its default policy requirements will be cleared. The next time you select the type, you will need to configure its policy requirements.

Configuring Usage Protection Measures

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane on the left, choose Risk Assessment > Security Baseline Configuration.
  4. Click the Use tab.
  5. Click Configure Measures. The Configure Measure page is displayed.

    • Built-in measures: DSC provides built-in measures for different data phases based on Huawei Cloud data security governance experience. For details about the built-in measures, see Built-in Measures.
    • Custom Measures: The added custom measures are displayed in the baseline policy list.

  6. You can uncheck the box to deselect unnecessary measures. The deselected measures will not be displayed in the policy baseline list.
  7. Click Add. The Add Custom Protection Measure page is displayed.

    1. Enter the measure name and measure description. Click OK to return to the Configure Measure page, where you can see the added measure.
    2. Click Edit in the Operation column to modify a measure, or click Delete to delete an unnecessary measure.

  8. Click OK to view the configured measures in the policy baseline list.

Configuring Data Protection Types for Usage

  1. On the Use tab page, click Configure Data Protection Type.
  2. Built-in Data Protection Type: If a protection type is deselected, the type will not appear in the baseline policy list, and the default policy requirements of this type will be cleared. You will need to customize the policy requirements for the protection type the next time.

    • General Data Protection: This type of protection is applied to data that has not been classified based on sensitive data identification.
    • Leveled Data Protection Type: Leveled data protection is applicable to data that has been classified and graded. DSC includes built-in sensitive data levels from L1 to L4. If this option is deselected, it will not be displayed in the policy baseline list.

  3. Custom Data Protection Type: The added custom data protection types are displayed in the policy baseline list.

    Select a custom level from the drop-down list box. If no custom level is available, create one by referring to Adding a Sensitivity Level.

  4. Click OK. In the policy baseline table, view the data protection type.

Modifying Data Usage Protection Requirements

  1. On the Use tab page, click Modify Protection Requirements.

    For example, select Not required, Suggestion, or Required from the drop-down list in the Access Authentication and Control column of the General Data Protection row.

  2. Click Save Changes. You can also click Cancel Changes in the upper left corner to cancel the modification and return to the previous protection requirements.