How Do I Prevent Personal Sensitive Data From Being Disclosed During Development and Testing?
Sensitive data refers to information that, if accessed, disclosed, or misused by unauthorized persons, may pose serious risks to individuals or organizations.
- For individuals, this includes personal information such as ID card numbers, home addresses, employers, and bank card numbers.
- For enterprises or organizations, sensitive data encompasses core information such as customer data, financial details, technical information, and major decisions.
The static data masking function provided by Huawei Cloud Data Security Center (DSC) allows you to convert a large amount of data at a time based on the masking rules. It is usually used to deliver sensitive data in the production environment to the development, test, or outside environment for development and test, data sharing, and data research.
Common Causes of Data Breaches
- Insider leakage
- Laptops or mobile devices are lost or stolen.
- Sensitive data or storage is accessed by unauthorized personal
- Sensitive data is sent, printed, and copied by employees.
- Sensitive data is accidentally transmitted out.
- Leakage caused by external attacks
- Data access is uncontrollable, or there are security vulnerabilities in the data storage system.
- Improper configurations allow external attacks.
- Sensitive data or storage is accessed by unauthorized personal
Video Tutorial
Step 1: Buying the DSC Professional Edition
- Log in to the DSC console.
- Click
in the upper left corner and select a region or project. - If you are a first-time user, click Buy DSC.
- On the Buy DSC page, select Region and Project from the drop-down lists.
Only one DSC edition can be purchased in a region.
Figure 1 Selecting a region and edition
- Select an edition. It can be Standard or Professional. For details, see Table 1.
Table 1 Specifications of different DSC editions Edition
Database Quantity
OBS Capacity
API Calls
Function
Standard
2
100 GB
Not supported
- Asset Map
- Asset Management
- Sensitive Data Identification
- Data Security Operations
Professional
2
100 GB
1 million
- Asset Map
- Asset Management
- Sensitive Data Identification
- Data Masking
- Data Watermarking
- Data Security Operations
- Dynamic Data Masking and Watermarking API Calling
- Select the quantity for Database Expansion Package and OBS Expansion Package. Select AI-assisted Data Security Function Expansion Package.
To use AI-assisted data security, data security zones, or the trusted key space, you need to purchase the AI-assisted Data Security Function Expansion Package.
Figure 2 Selecting expansion packages
- Set Required Duration. Select the required duration from one month to three years.
Select Auto-renew to enable the system to renew your service by the purchased period when the service is about to expire.
- Click Next.
If you have any questions about the pricing, click Pricing details.
- Confirm the order information and agree to the DSC disclaimer by selecting I have read and agree to the Data Security Center Service Statement and click Pay Now.
- Select a payment method to pay for your order on the displayed page.
Step 2: Identifying Sensitive Data
- In the navigation pane, choose Classification and Grading > Tasks.
- Click Create Task. In the displayed dialog box, configure the basic parameters. Set other optional parameters as required.
Table 2 Parameters for creating a sensitive data identification task Parameter
Description
Example Value
Task Name
You can customize the task name.
The task name must:
- Contain 4 to 255 characters.
- Consist of letters, digits, underscores (_), or hyphens (-).
- Start with a letter.
- Be unique.
test
Data Source
Select one or more data sources.
- OBS: After DSC is authorized to access your Huawei Cloud OBS asset, DSC will identify the sensitive data in it. For details about how to add OBS assets, see Adding an OBS Asset.
- Database: DSC will identify the sensitive data in the authorized databases. For details about how to authorize a database, see Adding and Authorizing Database Assets.
- Big Data: DSC will identify the sensitive data in the authorized big data assets. For details about how to authorize big data assets, see Adding and Authorizing Big Data Assets.
- LTS: DSC will identify the sensitive data in the authorized LTS assets. For details about how to add a log stream, see Adding a Log Stream.
Database > gbx-jiami
Identification Template
You can select a built-in or custom template. DSC displays data by level and category based on the template you select. For details about how to create an identification template, see Customizing a Rule.
General Cloud Data Security Classification Template
Identification Period
Set the execution policy of the data identification task.
- Once: The task will be executed once at a specified time.
- Daily: The task is executed at a fixed time every day.
- Weekly: The task is executed at a specified time every week.
- Monthly: The task is executed at a specified time every month.
Once
Identification Method
Select incremental or full identification.
- Incremental identification: Identified data will be skipped.
- Full identification: All data will be checked.
Full identification
Identification Method
Select incremental or full identification.
- Incremental identification: Identified data will be skipped.
- Full identification: All data will be checked.
Full identification
When to Execute
This parameter is displayed when Identification Period is set to Once.- Now: Select the option and click OK, the system executes the data identification task immediately.
- As scheduled: The task will be executed at a specified time.
Now
- Click OK. The sensitive data identification task list is displayed.
- When the status of the identification task changes to Identification completed. Click View Result in the Operation column to go to the result details page.
The Birthday and PhoneNumbers columns are identified as sensitive data.
- In the Operation column of an asset, click View Details. Figure 3 Categorizing and leveling results

- Perform operations described in Step 3: Performing Static Data Masking to mask the sensitive data in the Birthday and PhoneNumbers columns of the info1 table in the gbx-jiami database.
Step 3: Performing Static Data Masking
You can use DSC to create data masking tasks for databases, and Elasticsearch, MRS, and Hive assets. This section describes how to create a static data masking task for a database. For details about how to mask data for other data sources, see Creating a Static Data Masking Task.
- In the navigation pane on the left, choose .
- Click Create Task to configure the data source.
Select all data types if you want a complete table that contains all types of data after the data masking is completed.
Figure 4 Data source configuration
- Click Next to switch to Set Masking Algorithm. Figure 5 Configuring the data masking algorithm
- Click Next to switch to the Configure Data Masking Period page and configure the data masking period.
- Click Next to the Set Target Data page and configure the storage location of the table generated after data masking. Figure 6 Configuring the storage location of the table generated after data masking
- Click Finish to return to the database data masking task list. Click
to enable the masking task and then Execute in the Operation column to execute the task. If the status changes to Completed, the data masking task has been successfully executed.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot