Risk List
On the DSC risk list page, you can view the overall risk score, asset sensitivity level overview, top 5 asset levels, and risk details of each asset type.
Under Risk Details, asset risks are displayed by security level. Moreover, handling solutions are provided based on the configured security baseline.
Prerequisites
There are added OBS assets or authorized big data or database assets. For details, see Adding and Authorizing Data Assets in DSC.
Checking the Risk List
- Log in to the DSC console.
- Click
in the upper left corner and select a region or project. - In the navigation pane on the left, choose .
- Risk Score: It shows the Security Score of all your assets. You can click
next to Scoring Rules to check the score calculation rule. - Asset Sensitization Level Overview: It displays the classification results of sensitive data in your assets.
- Top 5 Asset Levels: It displays the five asset levels with the most assets.
- Risk Details:
- Select an asset type (OBS, Big Data, or Database) to check the asset list. You can check the Instance, Type/Engine Type, and Security Level.
- Click
next to the instance name to view the risk details of each asset type. The following uses a database as an example to describe how to determine and handle asset risks. Table 1 Risk details description No. in Figure 1
Description
①
Security level. L4 indicates level-4 sensitive data.
②
Scan result of the asset policy.
The value can be No risk, Low risk, Medium risk, or High risk.
③
The security baseline policy configured in Configuring Security Baselines. DSC checks whether the baseline policy configured for your assets is appropriate.
For example, in Figure 1, encryption is not required for L4 data in the security baseline configuration.
④
Determine whether to handle the detected risk based on the information in ①②③. You are advised to handle the risks as follows:
- If the identification result in ② is No risk, or it is High risk, Medium risk, or Low risk, but you can confirm that there are no configuration risks, you can click Ignore. The ignored risk will not be included in the asset score. NOTICE:
If you select Ignore for an identified risky asset, you have accepted the asset risk identified by DSC. However, the data asset is still risky. Exercise caution.
- If the identification result in ② is High risk, Medium risk, or Low risk, and you have confirmed that the current configuration is risky based on the baseline configuration requirements in ③, click Modify, Enable, or Details, and view or modify the corresponding policy.
- If the identification result in ② is No risk, or it is High risk, Medium risk, or Low risk, but you can confirm that there are no configuration risks, you can click Ignore. The ignored risk will not be included in the asset score.
- Risk Score: It shows the Security Score of all your assets. You can click
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
