User Guide
Example DAI Setup
The following are examples of how to:
-
Set up a Data Asset Inventory (DAI)
-
Add Assets
-
Add Targets
-
-
Create a Scan
-
Add a new Scan
-
Run a Scan
-
-
Review the results in SDV3
Sample DAI Setup
Goal: Set up a DAI to scan an SQL server for all databases that contain credit card numbers and determine the SDV3 score to determine their valuation, volume, vulnerability.
Add a New Asset to your DAI
1. In the left Sensitive Data Platform menu, click Data Asset Inventory.
2. Click Data Assets and Targets.
3. Click +New Asset.
4. Expand the Technical Info section and fill in the following (required):
a. Name: Type the name of the Asset. For example: SQL Server Blue.
b. Description: Type a short description of the Asset that gives you an easy way to remember the Asset and its contents. For example: My SQL server.
c. Status: Select an option from the drop-down list. For example: Active.
5. Expand the Owner & Department section and fill in the following (required):
a. Asset Owner: Click an option from the drop-down list or click Add to add a new owner.
b. Administering Department: Click an option from the drop-down list or click Add to add a new department.
6. Expand the Hosting section and fill in the following (optional):
a. Hosting Provider: Type the hosting provider name.
b. System ID: Type the System ID.
c. Hosting Locations: Click +Hosting Locations and select and click Add Location, search for existing locations, or click +Hosting Locations again to add a new location.
7. Expand the Security Measures section and fill in the following (required):
a. Organizational Security Measures: These are policies on how to use this data that affect the overall security without a physical component. For example, a password policy or PCI training. Do the following:
1) Click +Organization Security Measures.
2) Click +Organization Security Measures again.
3) Name: Type a descriptive name such as Password Policy.
4) Description: Type a short description of what the police is, such as password minimum length, special characters, restricted characters, etc.
5) Vulnerability Reduction: Use the updown number control to set a value of how much using this Security Measure reduces the vulnerability of the data. This can be valued from one (lowest) to ten (highest).
6) Click Save & Add to add or Cancel to discard and start over.
7) Locate the new Security Measure in the list and click Add Selected.
b. Technical Security Measures: These are physcial measures that reduce the vulnerability of your data. For example, firewalls, anti-virus software, malware intrusion, etc. Do the following:
1) Click +Technical Security Measures.
2) Click +Technical Security Measures again.
3) Name:Type a description name, such as Firewall Software.
4) Description: Type a short description of the measure, such as software name, admin, etc.
5) Vendor (optional): Select the vendor name from the drop-down list.
6) Vulnerability Reduction: Use the updown number control to set a value of how much using this Technical Security Measure reduces the vulnerability of the data. This can be valued from one (lowest) to ten (highest).
7) Click Save & Addto add or Cancel to discard and start over.
8) Locate the new Technical Security Measure in the list and click Add Selected.
8. Click Next.
Associate aTarget with Your Asset
1. On the Target tab, select the following:
a. Asset Type (required): Choose the asset type from the drop-down list. For example: My SQL Server.
b. Asset Subtype (optional): Choose the subtype from the drop-down list.
c. Tag Group ID (optional): Choose the ID from the drop-down list.
2. In the All Targets section, select your new Target. You can search for it by name or locate it in the All Targets section.
3. Click the right arrow to add it to the Selected Targets section.
4. You can click the left arrow of a Target in the Selected Targets section to remove the Target.
5. Click Next.
Add Data Content
1. On the Data Content tab, do the following:
a. Click +Data Content.
b. Click Create New Data Content.
c. Name: Type the name of the content. For example: My New Data Content.
d. Description: Type a short description.
e. Click Save & Add to add or Cancel to discard and start over.
f. Select the new content from the list and click Add Selected.
Click Next.
Add a Business Process
On the Business Processes tab, you can add a process you have set up. This is optional.
1. Click Business Processes.
2. Select a business process from the list.
3. Click Attached Selected.
4. Click Next.
Review Your Asset
On the Summary tab, you can review all your information and you can view whether or not you have met all the required data fields. Do the following:
1. Review each section for accuracy.
2. Ensure all required fields are filled out.
3. Click Finish & Save to save your Asset.
Add a New Target to Scan
If you need to add a new Target, use the following steps.
1. On the Data Assets and Targets screen, click the Targets tab.
2. Click +Add Target.
3. Target Name: Type the target name. For example: My SQL Server.
4. Target Type: Click Database.
5. Click a database to configure. For example: My SQL.
6. Connection String: Type the string needed to connect to the database.
7. Click Save to add or Cancel to discard.
8. You can search for your Target by name or in the All Targets section.
Create and Run a New Scan
1. Use the steps in Create a New Scan to create a scan using the Asset and Targets you have just created. [This is where the specific parameters of the credit card scan will go].
2. Run the new Scan:
a. In the Scans section, locate your new Scan,
b. Click the ellipse menu and select Run Scan Now.
c. When the Scan is finished, it will display a status of Done, View Results.
Review SDV3
When you new Scan is completed, the data points will be displayed in your SDV3 dashboard.