Example DAI Setup

The following topics provide examples of how to:

  • Set up a Data Asset Inventory (DAI)

    • Add Assets

    • Add Targets

  • Create a Scan

    • Add a new Scan

    • Run a Scan

  • Review the results in SDV3

 

Sample DAI Setup

  • Goal: Set up a DAI to scan an SQL server for all databases that contain credit card numbers and determine the SDV3 score to determine their valuation, volume, vulnerability.

Add a New Asset to your DAI

Procedure:

  1. In the left Sensitive Data Platform menu, click Data Asset Inventory.

  2. Click Data Assets and Targets.

  3. Click +New Asset.

  4. Expand the Technical Info section and fill in the following (required):

    • Name: Enter the name of the Asset. For example: SQL Server Blue.

    • Description: Enter a short description of the Asset that gives you an easy way to remember the Asset and its contents. For example: My SQL server.

    • Status: Select an option from the drop-down list. For example: Active.

  5. Expand the Owner & Department section and fill in the following (required):

    • Asset Owner: Click an option from the drop-down list or click Add to add a new owner.

    • Administering Department: Click an option from the drop-down list or click Add to add a new department.

  6. Expand the Hosting section and fill in the following (optional):

    • Hosting Provider: Enter the hosting provider name.

    • System ID: Enter the System ID.

    • Hosting Locations: Click +Hosting Locations and select and click Add Location, search for existing locations, or click +Hosting Locations again to add a new location.

  7. Expand the Security Measures section and fill in the following (required):

    1. Organizational Security Measures: These are policies on how to use this data that affect the overall security without a physical component. For example, a password policy or PCI training.
      Do the following:

      1. Click +Organization Security Measures.

      2. Click +Organization Security Measures again.

        • Name: Enter a descriptive name such as Password Policy.

        • Description: Enter a short description of what the policy is, such as password minimum length, special characters, restricted characters, etc.

        • Vulnerability Reduction: Use the up-down number control to set a value of how much using this Security Measure reduces the vulnerability of the data. This can be valued from 1 (lowest) to 10 (highest).

  8. Click Save & Add to add or Cancel to discard and start over.

  9. Locate the new Security Measure in the list and click Add Selected.

  10. Technical Security Measures: These are physical measures that reduce the vulnerability of your data. For example, firewalls, anti-virus software, malware intrusion, etc.
    Do the following:

    1. Click +Technical Security Measures.

    2. Click +Technical Security Measures again.

      • Name:Enter a description name, such as Firewall Software.

      • Description: Enter a short description of the measure, such as software name, admin, etc.

      • Vendor (optional): Select the vendor name from the drop-down list.

      • Vulnerability Reduction: Use the up-down number control to set a value of how much using this Technical Security Measure reduces the vulnerability of the data. This can be valued from 1 (lowest) to 10 (highest).

  11. Click Save & Addto add or Cancel to discard and start over.

  12. Locate the new Technical Security Measure in the list and click Add Selected.

  13. Click Next.

Associate a Target with Your Asset

Procedure:

  1. 1. On the Target tab, select the following:

    1. Asset Enter (required): Choose the asset type from the drop-down list. For example: My SQL Server.

    2. Asset Subtype (optional): Choose the subtype from the drop-down list.

  2. Tag Group ID (optional): Choose the ID from the drop-down list.

  3. In the All Targets section, select your new Target. You can search for it by name or locate it in the All Targets section.

  4. Click the right arrow icon to add it to the Selected Targets section.

  5. You can click the left arrow of a Target in the Selected Targets section to remove the Target.

  6. Click Next.

Add Data Content

Procedure:

  1. On the Data Content tab, do the following:

    1. Click +Data Content.

    2. Click Create New Data Content.

      • Name: Enter the name of the content. For example: My New Data Content.

      • Description: Enter a short description.

    3. Click Save & Add to add or Cancel to discard and start over.

  2. Select the new content from the list and click Add Selected.

  3. Click Next.

Add a Business Process

On the Business Processes tab, you can add a process you have set up. This is optional.

Procedure:

  1. Click Business Processes.

  2. Select a business process from the list.

  3. Click Attached Selected.

  4. Click Next.

Review Your Asset

On the Summary tab, you can review all your information and you can view whether or not you have met all the required data fields.

Do the following:

  1. Review each section for accuracy.

  2. Ensure all required fields are filled out.

  3. Click Finish & Save to save your Asset.

Add a New Target to Scan

If you need to add a new Target, use the following steps.

  1. On the Data Assets and Targets screen, click the Targets tab.

  2. Click +Add Target.

  3. Target Name: Enter the target name. For example: My SQL Server.

  4. Target Enter: Click Database.

  5. Click a database to configure. For example: My SQL

  6. Connection String: Enter the string needed to connect to the database.

    1. Sample connection string: Provider=MySQLProvider;DB Name=mysqlserverLarge;Server=10.0.1.99;Port=9999;Username=userJohn;Password=JohnsPassword;DB Type=9;

  7. Click Save to add or Cancel to discard.

  8. You can search for your Target by name or in the All Targets section.

Create and Run a New Scan

  • Use the steps in Create a New Scan to create a scan using the Asset and Targets you have just created.

  • [This is where the specific parameters of the credit card scan will go].

Run the new Scan:

  1. In the Scans section, locate your new Scan:

    1. Click the ellipse menu and select Run Scan Now.

    2. When the Scan is finished, it displays a status of Done, View Results.

Review SDV3

When you new Scan is completed, the data points are displayed in your SDV3 dashboard.