Allowing or Disallowing Access to Cloud Assets
Before using DSC to check your cloud asset data security, you need to authorize DSC to access cloud assets. This section describes how to grant or revoke permissions for accessing OBS buckets, databases, big data, MRS, and LTS. The system will create an agency for you to use DSC.
Background
Cloud asset authorization is different from asset center data authorization.
- With cloud asset authorization, DSC can access other cloud products that provide data services.
- With asset center data authorization, DSC can access data stored in cloud products, such as files, databases, and data spaces in OBS buckets.
After DSC is authorized to access cloud assets, you need to authorize asset center data so that sensitive data identification and data masking can be performed. For details, see Adding and Authorizing Data Assets in DSC.
Prerequisites
The user has been bound to a user group with the Tenant Administrator permission using IAM. For details, see Creating a User Group and Assigning Permissions.
Constraints
- After permissions are granted, DSC will be able to access your OBS buckets, databases, big data instances, and other cloud assets as needed.
After DSC is granted permissions for accessing the OBS bucket to obtain the logs, fees are incurred. For details, see Requests.
- After the permissions are revoked, ensure that your assets have no ongoing tasks. DSC will delete your agencies and assets and all related data. Exercise caution when performing this operation.
- If an organization member has been added to DSC using Multi-Account Management, the assets of all member accounts (except LTS assets, which do not support multi-account management) can be managed after the administrator or delegated administrator approves the authorization.
Agency Policies Obtained After Access to Assets Is Allowed
| Asset | Policy | Scope | Remarks |
|---|---|---|---|
| OBS | OBS Administrator | Global | Used to configure OBS logs, obtain the OBS object list, download OBS objects, and obtain OBS delivery logs. |
| Database | ECS ReadOnlyAccess | Regional | Used to obtain the list of ECSs where databases are built. |
| RDS ReadOnlyAccess | Regional | Used to obtain the RDS database list and related information. | |
| DWS ReadOnlyAccess | Regional | Used to obtain the DWS instance list. | |
| DDS ReadOnlyAccess | Regional | Used to obtain the DDS list. | |
| VPC FullAccess | Regional | Used to establish network connection and create VPC ports and security group rules | |
| KMS CMKFullAccess | Regional | Used to perform encryption using KMS in data masking. | |
| GaussDB ReadOnlyAccess | Regional | Used to obtain the GaussDB list. | |
| Big data | ECS ReadOnlyAccess | Regional | Used to obtain the list of ECSs where big data sources reside. |
| CSS ReadOnlyAccess | Regional | Used to obtain the CSS data cluster list and data indexes. | |
| VPC FullAccess | Regional | Used to establish network connection and create VPC ports and security group rules | |
| KMS CMKFullAccess | Regional | Used to perform encryption using KMS in data masking. | |
| MRS | MRS CommonOperations | Regional | Used for cluster query and task creation. |
| LTS | LTS ReadOnlyAccess | Regional | Used to read LTS log groups or log streams. |
Procedure
- Log in to the DSC console.
- Click
in the upper left corner of the management console and select a region or project. - Choose . In the upper left corner of the displayed page, click Modify next to Cloud Asset Authorization. The Authorize Access to Cloud Assets page is displayed.
- On the displayed page, allow or disallow DSC to access your cloud assets. For details, see Table 2. Figure 1 Allowing access to cloud assets
Table 2 Parameter description Parameter
Description
Asset
- OBS: OBS assets.
- Database: database assets. For details, see Constraints.
- Big data: big data assets.
- MRS: assets in MapReduce Service (MRS).
- LTS: assets in Log Tank Service (LTS).
Agency Policies Obtained After Access to Assets Is Allowed describes the agency policies obtained after the access to assets is allowed.
Authorization Status
Authorization Status- Authorized
- Unauthorized
Operation
Click the following toggle buttons to allow or disallow access to your assets:
: Unauthorized
: Authorized
Follow-up Operations
- Go to the Asset Center page, add your assets, and authorize DSC to access the assets. For details, see Adding and Authorizing Data Assets in DSC.
- Manage and check the security posture of your asset data at any time. For details, see Managing Asset Groups, Asset View, and Viewing the Data Security Situation on the Asset Map.
- Use identification templates to classify, grade, and manage your data assets. For details, see Risk Assessment.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot