Help Center/ Data Security Center/ Best Practices/ OBS Data Security Solution/ Checking OBS Security Configuration Compliance
Updated on 2026-09-30 GMT+08:00

Checking OBS Security Configuration Compliance

Scenarios

DSC can evaluate and verify the security configuration compliance of OBS, for example, whether the ACL and encryption policy are configured, and provide handling suggestions for detected configuration risks. You are advised to handle configuration risks in a timely manner based on the handling suggestions to enhance the basic security configuration of data assets in OBS.

Solution Architecture

The following table lists the baseline risk check items supported by DSC for OBS.

Table 1 Baseline check items

Policy Name

Check Item

Description

Server-side encryption

OBS - Enabling OBS server-side encryption

Check whether encryption is enabled for OBS.

Security measures such as encryption must be configured for data storage to ensure data confidentiality and integrity.

Bucket policy

OBS - Checking whether the OBS bucket policy is public read and public read/write

Check whether OBS logs have data leakage risks such as public read/write, or whether access control is enabled for the project where sensitive data is stored.

OBS audit

OBS - Checking whether OBS audit is enabled

Check whether log audit is enabled for OBS files.

DSC identifies sensitive data based on its identification rules and monitors events related to the sensitive data. You can check results in the event list and handle the abnormal events as needed.

To complete the preceding baseline security check and handling, perform the following steps:

  1. Creating an OBS bucket: Create an OBS bucket, and simulate a DSC baseline check on OBS data.
  2. Authorizing access to OBS buckets and interconnecting with DSC: Baseline check can be performed on OBS data only after the authorization.
  3. Security baseline configuration: DSC has default security baseline configurations, which can be adjusted based on service requirements. By default, a security baseline check is performed on connected OBS assets at about 02:00 every day.
  4. Viewing and handling security risks: Handle detected configuration risks in a timely manner based on the check results.

Prerequisites

Step 1: Create an OBS Bucket

  1. Go to the OBS console, and choose Buckets from the navigation pane on the left.
  2. Click Create Bucket in the upper right corner.
  3. On the Create Bucket page, set the parameters below, retain default settings for other parameters, and click Create Now.

    • Region: Select the region where DSC is purchased.
    • Data Redundancy Policy: Select Single-AZ storage.
    • Storage Class: Select Standard.
    • Block Public Access: Enable this function.
    • Bucket Policy: Select Private.

    For details about how to create an OBS bucket, see Creating an OBS Bucket.

Step 2: Authorize Access to the OBS Bucket and Interconnect with DSC

  1. Log in to the DSC console.
  2. Choose Asset Center > Asset Management. In the upper left corner of the displayed page, click Modify next to Cloud Asset Authorization. The Authorize Access to Cloud Assets page is displayed.
  3. On the displayed page, enable OBS asset authorization.
  4. Return to the Asset Management page, and click OBS under OBS. The OBS asset list is displayed.
  5. Click Add User-built Bucket in the upper left corner. In the displayed dialog box, select the OBS buckets to be added.
  6. Click OK. If the added OBS bucket is displayed in the list, the adding is successful.

Step 3: Configure an OBS Security Baseline Policy

Set the protection requirements of Access Authentication and Control, Data Usage Auditing, Data Masking, and Public Network Data Protection to Suggestion or Required. DSC then checks whether OBS configurations meet the baseline requirements based on the configured baseline policy.

  1. In the navigation pane on the left, choose Risk Assessment > Security Baseline Configuration.
  2. In the Use tab, click Modify Protection Requirements.

    Configure the settings as shown in the following figure.

  3. Click Save Changes. You can also click Cancel Changes in the upper left corner to cancel the modification and return to the previous protection requirements.

Step 4: View and Handle Security Risks

By default, a security baseline check is performed on connected OBS assets at about 02:00 every day. The check results are displayed in the risk list.

Viewing OBS Risk Check Results

  1. In the navigation pane on the left, choose Risk Assessment > Risks.
  2. Under Risk Details, click OBS to view the OBS asset list, click in front of an instance name, and view asset risk details.

    Figure 1 Risk details
    Table 2 Risk details description

    No. in Figure 1

    Description

    ①

    Security level. L4 indicates level-4 sensitive data.

    ②

    Scan result of the asset policy.

    The value can be No risk, Low risk, Medium risk, or High risk.

    ③

    Security baseline policy configured in Step 3: Configure an OBS Security Baseline Policy. DSC checks whether the baseline policy configured for your assets is appropriate.

    ④

    Determine whether to handle the detected risk based on the information in ①②③. You are advised to handle the risks as follows:

    • If the identification result in ② is No risk, or it is High risk, Medium risk, or Low risk, but you can confirm that there are no configuration risks, you can click Ignore. The ignored risk will not be included in the asset score.
      NOTICE:

      If you select Ignore for an identified risky asset, you have accepted the asset risk identified by DSC. However, the data asset is still risky. Exercise caution.

    • If the identification result in ② is High risk, Medium risk, or Low risk, and you have confirmed that the current configuration is risky based on the baseline configuration requirements in ③, click Modify, Enable, or Details, and view or modify the corresponding policy.

Handling Risky Items

On the risk details page of the OBS risk list, the following situations may occur. Select a solution as required.

  • Enable server-side encryption: Go to the OBS console and enable server-side encryption.
  • Modify the bucket policy: Click Modify to go to the OBS console. You are advised to set Bucket Policy to Private. In this way, the bucket owner has full permissions on the bucket. Other users have no access permissions without authorization. If you require public access, choose a desired bucket policy here or configure the bucket ACL after creation.

    For details about how to configure a bucket policy, see Configuring a Bucket Policy.

  • Enabling OBS audit: Click Enable. Locate the OBS asset and click Enable Audit in the Operation column. In this way, you can easily manage and view records of abnormal operations on the OBS bucket. Enabling OBS usage audit incurs additional request fees. Confirm whether to enable this function.
  • Ignore risk: If the identification result is No risk, or it is High risk, Medium risk, or Low risk, but you can confirm that there are no configuration risks, you can click Ignore. The ignored risk will not be included in the asset score.

    If you select Ignore for an identified risky asset, you have accepted the asset risk identified by DSC. However, the data asset is still risky. Exercise caution.