Background Information
The Data Security Center provides capabilities such as automatic identification of sensitive data, classification and grading, big data security auditing, and data masking. It delivers an integrated, full-domain solution for data leak prevention and security on the cloud.Procedure
- On the Data Security Center product page, click Buy Now to open the purchase page.
-
Set the version specifications on the purchase page:
- [Required] Product Type: Select Data Security Center (Data Discovery, Classification and Grading, Masking, and Leak Prevention).
- [Required] Version: Select the Basic plan. You can select the higher-tier Business plan based on your security needs.
- [Required] Database Management: You must select On.
- [Required] Number of Database Instances: Purchase based on the actual number of database instances that store DingTalk data. Purchase at least 1. If the data obtained from DingTalk is stored in 2 database instances, purchase 2.
- [Optional] OSS Data Management: If no sensitive files are stored, you can select Close. If sensitive files such as ID card photos or user roster spreadsheets are stored, we recommend that you select On and purchase based on usage. This item is optional.
- [Required] Subscription Duration: Select at least 1 year and select Auto-renew on Expiration.
- The Data Security Center supports the identification and protection of data products in the following domestic regions: Hangzhou, Shanghai, Beijing, Shenzhen, Zhangjiakou, Hohhot, and Qingdao. Make sure your database instances are purchased within these regions.
- After the purchase is complete, go to the Data Security Center console and use the Configuration Guide to configure it.
- Click Sync to automatically sync assets on the cloud to the Data Security Center.
- For asset authorization, click Go to Configure to open the asset configuration page.
- Select structured data, and configure authorization for the database instances that store data obtained from the DingTalk platform (pushed via RDS or called through OpenAPI). You do not need to configure authorization for instances that store data collected by your own business apps that are not on DingTalk. Note Authorization configuration is slow when there are many databases. We recommend that you set no more than 20 databases per instance.
- After you complete the authorization configuration, in the Action column on the right of the authorized instance, click One-Click Connect to bind the authorized assets.
-
Click Data Sorting > Identification Configuration:
- Template Configuration: Use the built-in security classification and grading template of Alibaba Group and Ant Group.
- Template Details: Set the rule configuration to the On state.
FAQ
-
How does the VPC + Data Security Center + Compute Nest deployment method protect DingTalk private data? How does it prevent service providers from exporting DingTalk internal private data?
Answer:
- Compute Nest can detect security risks. It pushes alerts for high-risk configurations, vulnerabilities, or hacker intrusions.
- The Data Security Center identifies stored sensitive data and audits and alerts on suspected data leak operations, such as batch data export.
- Does the Data Security Center modify the original data in the database? Answer: No.
- Does the Data Security Center intercept and mask queried data or data being written to the database? Answer: No. The currently recommended version only identifies sensitive data. It does not process the data and does not affect your business.
-
How does the Data Security Center monitor databases?
Answer:
- Monitoring is based on authorization. Sensitive data is detected only when authorization is granted. DingTalk Security focuses on protecting data synced out from the platform. Product solution providers only need to authorize instances that store data obtained from the DingTalk platform, in accordance with the platform’s security requirements.
- If a product solution provider revokes authorization, or if DingTalk Security discovers falsified authorization through audit analysis and the provider refuses to make corrections after notification, the provider will be subject to point deductions and app removal in accordance with the security regulations.
-
When the Data Security Center monitors data and detects a risk, how does it provide alerts? What is the handling mechanism?
Answer:
- Sign in to the Data Security Center console to view the specific risk alerts and content.
- Product solution providers can handle the risks based on the risk alerts or by consulting DingTalk Security. For high-risk alerts that DingTalk Security is monitoring, it provides handling recommendations.
- DingTalk receives pushed high-risk alert notifications. DingTalk Security decides whether to follow up and notify the product solution provider to handle the risk based on the severity indicated in the alert notification.
- If the issue is left unhandled, will the app be removed or will any locking operation be applied to the database? Answer: No operation will be performed on the database. However, if a high-risk alert is left unhandled for a long time or a security violation is determined (for example, exporting data from the DingTalk platform to another business system), the app will be subject to point deductions and removal after communication with the app service provider, in accordance with the relevant requirements of the DingTalk platform’s security regulations.
-
If a table in a product solution provider’s app database stores a record of user data that contains both sensitive data obtained from the DingTalk platform and user data collected by the provider’s own app, does exporting this user record trigger an audit alert from the Data Security Center?
Answer:
- In principle, exporting user data requires the user’s authorization and consent, and the data can only be used within the authorized scope. Therefore, product solution providers should establish an approval and audit mechanism for user data export to prevent user data from being misused or leaked.
- The sensitive data identification and data leak prevention monitoring and auditing of the Data Security Center does not distinguish between data synced from the platform and self-collected data.
- The Data Security Center audits and generates alerts for suspected leak operations, such as batch data export. Normal calls by an application generally do not trigger alerts.
- If you no longer integrate with DingTalk in the future, what do you need to do to restore public network deployment? Do you need to perform operations such as a data audit? Answer: After you stop integrating with DingTalk, you need to notify the organization customers who use the partner app on DingTalk to export their own data. After you delete the customer data obtained from the DingTalk platform and the collected DingTalk organization customer data, and DingTalk staff verify and confirm the deletion, you can unbind the authorization and exit the Compute Nest platform.