tencent cloud

Cloud Security Center

Data Identification

Unduh
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-09-14 15:50:37
Diterjemahkan oleh AI
Data identification is a core governance module of DSPM, providing capabilities for business scenarios such as compliance inventory of data assets, sensitive data control, and dedicated protection of critical data.

Operation Overview

Operation
Applicable Scenarios
Enable data identification for the target database assets. The system will automatically scan sensitive data based on classification and grading templates.
View the classification and grading distribution, sensitive data details, and statistics after data identification scanning.
When built-in templates cannot meet business requirements, you can customize a data classification and grading system.
Switch the current classification and grading template in different business scenarios.
Quickly create a new template based on an existing template and reuse its classification and grading configurations.
Define specific sensitive data types in classification and grading identification, such as ID card numbers and mobile phone numbers.

Enabling Data Identification

1. Log in to the CSC console. In the left navigation pane, click Data Security Situation Management > Database Risk Monitor.
2. On the Database Risk Monitoring page, click the Instance list Tag.
3. On the Instance List Tag page, select the target database asset and click Data Identification in the Operation column.

4. In the data identification configuration window, select Immediate Identification or Scheduled Identification, and click OK after the configuration is complete.
5. After successful identification, the database asset table details are automatically refreshed, and data asset content tags are added.

Viewing Data Identification Results

1. On the Instance List Tag page, select the target database asset and click Instance ID.

2. On the Asset Details page, click the Data Identification Tag.
3. On the Data Identification Tag page, the classification and grading details under the current classification and grading template are displayed. Click Database Name, Table Name to view the classification and grading identification status of specific databases, tables, and fields.

Classification and Grading Management

Creating a Classification and Grading Template

A classification and grading template is a standardized data classification and grading standard generated by configuring the relationships among categories, grades, and data items. It serves as the unified standard for data classification and grading identification.
1. Log in to the CSC console. In the left navigation pane, click Data Security Situation Management > Database Risk Monitor.
2. On the Database Risk Monitoring page, click Classification and Grading Management to open the Classification and Grading Management panel.

3. On the Classification and Grading Tag page, click Create Template.
4. In the Create Template dialog box, configure the basic template information:
Configuration Item
Description
Template Name
Custom template name, up to 64 characters.
Description
Classification and grading template description, up to 200 characters.
Classification Scheme
Used to associate corresponding grades with data items during template configuration. Only existing grading schemes can be selected. If no grading scheme meets your requirements, click Create Grading Scheme to quickly create one.
5. Click OK to create the classification and grading template.
6. After creation, select the created template on the Classification and Grading Tag page and click Configure to configure the classification and grading template.

7. On the template configuration page, click the button

to add the required categories. Quick add is also supported.
8. After the category is added, select the target category and click Add Data Item.
9. In the Add Data Item dialog box, select the data items to associate with the category and configure a grade for each data item.
10. Repeat the preceding steps as needed to add multiple categories and data items to the template. This completes the creation of a classification and grading template.

Switching Classification and Grading Templates

Templates in the application are globally applicable. You can switch templates to select a classification and grading template that meets your requirements.
1. On the Classification and Grading Tag page, select the template you want to apply, and click Switch to This Template in the upper-right corner.

2. In the confirmation window, click OK to complete the switch.
Note:
The switch takes effect immediately and only affects new data identification results. Historical scan data records are retained.

Copying a Classification and Grading Template

You can quickly create a template by copying an existing one and then modify and adjust it based on the copied template.
1. On the Classification and Grading Tag page, select the template you want to apply, and click Copy.

2. In the Copy Template window, enter the template name and description, and click OK to complete the copy.
Note:
Built-in templates do not support editing or deletion. To make adjustments based on a built-in template, use the copy feature to create a duplicate and then modify it.

Creating a Data Item

A data item is the smallest rule unit used to identify sensitive data. It determines the sensitivity attribute of a field through matching logic such as keywords and regular expressions, and serves as the core rule basis for automatic scanning and identification of sensitive data. The system provides 797 built-in data items and also supports custom creation.
1. Log in to the CSC console. In the left navigation pane, click Data Security Situation Management > Database Risk Monitor.
2. On the Database Risk Monitoring page, click Classification and Grading Management to open the Classification and Grading Management panel.
3. In the Classification and Grading Management window, click the Data Item Tag.
4. On the Data Item tab, click Create Data Item.

5. On the Create Data Item page, configure the relevant data item settings, and click OK to create it.
Parameter
Description
Basic Information
Data item name
The data item name is the identifier of a category-data item, used to uniquely identify each data item in the system.
Description
The data item description provides detailed information about the identified data item, helping users better understand its purpose, function, and expected effect.
Enabling Status
Indicates whether this data item takes effect when a classification and grading task is executed.
Rule Configuration
Match logic
And: All conditions must be met for successful identification.
Or: Identification succeeds as long as any one of the conditions is met.
Recognition target
The recognition target refers to the object on which data recognition is performed. Multiple characteristics of the recognition target can be configured simultaneously, such as field names and content.
Recognition method
You can freely select the required recognition method (match/mismatch).
Recognition logic
Keyword: Keyword matching is a matching mode that identifies data by searching for specific keywords in the data. Once these keywords are found in the data, the data is marked and classified and graded.
Regular expression: Regular expression matching uses regular expressions to define complex matching patterns. Matching with regular expressions improves accuracy and flexibility.
Ignore Case
If "Ignore Case" is enabled, letter case is not distinguished during matching.
Full-text matching
Full-text matching refers to comparing the data to be recognized with the recognition content for exact consistency. If the data is exactly the same as the recognition content, it will be marked, classified, and graded.
6. After the configuration is complete, you can click Test to test and verify the configured identification rules.

Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan