After purchasing a Data Security Center (DSC) instance, you must enable the required features to use DSC to detect sensitive data in big data products such as TableStore, MaxCompute, AnalyticDB-MYSQL, and AnalyticDB-PG, or to audit databases.
Prerequisites
You have activated the Data Security Center Free Edition or purchased a paid instance of Data Security Center. For more information, see Data Security Center Free Edition or Purchase DSC.
You have granted DSC permissions to access Alibaba Cloud services. For more information, see Grant DSC permissions to access cloud resources.
View asset details
Log on to the Data Security Center console.
In the navigation pane on the left, choose Asset Center.
On the left side of the page, in the Big Data navigation bar, select the data type for which you want to enable features.
NoteAfter you purchase a DSC instance, an asset list sync task runs automatically the first time you log on to the console. You do not need to run this task manually. DSC automatically scans and syncs the asset list at 00:00 every day. Alternatively, you can go to the Asset Center page and manually run an Asset synchronization task. Asset synchronization is not supported for AnalyticDB-PG.
At the top of the Asset Center page, view the Total Assets, Feature Status, and Usage of Instances and Storage for the selected asset type.
You can click the number below a feature that is not enabled to filter the list.

Enable features
The available features vary by product type. To manually enable a feature, you can click the
icon. Some data types also support one-click enablement.
Enable features with one click
Only the TableStore and MaxCompute data types support one-click enablement.
On the left side of the page, in the Big Data navigation bar, select the data type for which you want to enable features.
In the Actions column of the target instance, click Enable.
In the Enable dialog box, select Scan assets and identify sensitive data now. if needed, and then click OK.
Manually enable features
TableStore
TableStore supports the Data Classification and Data Auditing features.
Data Auditing: Click the
icon for this feature and wait for it to be enabled.Data Classification
Click the
icon for the Data Classification feature.In the Enable Classification and Grading dialog box, configure Activation Method and Authorization Scope, and then click OK.
Configuration Item
Description
Activation Method
Only Service-Linked Role Access is supported.
Authorization Scope
Only Entire data source is supported.
Automatically create and start a default scan task
If you select this option, DSC automatically creates a default scan task after it is connected to the big data service.
You can go to the tab and click Default Tasks to view the task execution status. For more information, see Use a scan task to detect sensitive data.
MaxCompute
MaxCompute supports the Configuration Risks, Data Classification, and Data Auditing features.
For the Configuration Risks and Data Auditing features, click the
icon for each feature and wait for it to be enabled.Data Classification
Click the
icon for the Data Classification feature.In the Enable Classification and Grading dialog box, configure Activation Method and Authorization Scope, and then click OK.
Configuration Item
Description
Activation Method
Only Service-Linked Role Access is supported.
Authorization Scope
Only Entire data source is supported.
Automatically create and start a default scan task
If you select this option, DSC automatically creates a default scan task after it is connected to the big data service.
You can go to the tab and click Default Tasks to view the task execution status. For more information, see Use a scan task to detect sensitive data.
AnalyticDB-MYSQL
AnalyticDB-MYSQL supports the Configuration Risks, Data Classification, and Data Auditing features.
For the Configuration Risks and Data Auditing features, click the
icon for each feature and wait for it to be enabled.Data Classification
For the Data Classification feature, click the corresponding
icon.In the Enable Classification and Grading dialog box, configure Activation Method and Authorization Scope. Click OK.
Configuration Item
Description
Activation Method
Configure the account that is used to connect to the database for data detection. Only Manually enter username and password is supported.
Database Account
Configure the username and password that are used to connect to the database.
Authorization Scope
The scope of data detection.
Entire data source.
Manage authorization scope in the data source list: Select an authorization scope.
Automatically create and start a default scan task
If you select this option, DSC automatically creates a default scan task after it is connected to the database.
You can go to the tab and click Default Tasks to view the task execution status. For more information, see Use a scan task to detect sensitive data.
After the Data Classification feature is enabled, you can view the total number of authorized databases and the connection status of the database instance to the right of the switch.

Click the number to the right of the switch.
In the Authorization Scope panel, you can perform operations on the databases.
Edit databases
Select the check boxes of one or more databases.
Click Bulk Authorize below the list.
In the Bulk Authorize dialog box, modify the Database Account and Database Password, and then click OK.
Cancel database connections
Select the check boxes of one or more databases.
Click Bulk Cancel below the list. Then, click OK.
AnalyticDB-PG
AnalyticDB-PG supports the Configuration Risks, Data Classification, and Data Auditing features. Before you can enable these features, you must add an asset.
Add an asset
On the left side of the page, in the Big Data navigation bar, choose ADB-PG and click Add Asset.
In the Add Asset dialog box, configure the following parameters. Then, click Confirm.
Configuration Item
Description
Region
Select the region where the instance resides.
Instance Name
Select the name of an instance that is created in the region.
Database Name
Enter the name of the database.
Username
Enter the username that is used to connect to the database and configure permissions for the account.
Password
Enter the password that is used to connect to the database.
Enable features
For the Configuration Risks and Data Auditing features, click the
icon for each feature and wait for it to be enabled.Data Classification
Click the
icon next to Data Classification.In the Enable Classification and Grading dialog box, configure Activation Method and Authorization Scope. Click OK.
Configuration Item
Description
Activation Method
Configure the account that is used to connect to the database for data detection. Only Manually enter username and password is supported.
Database Account
Configure the username and password that are used to connect to the database.
Authorization Scope
The scope of data detection.
Entire data source.
Manage authorization scope in the data source list: Select an authorization scope.
Automatically create and start a default scan task
If you select this option, DSC automatically creates a default scan task after it is connected to the database.
You can go to the tab and click Default Tasks to view the task execution status. For more information, see Use a scan task to detect sensitive data.
After the Data Classification feature is enabled, you can view the total number of authorized databases and the connection status of the database instance to the right of the switch.

Click the number to the right of the switch.
In the Authorization Scope panel, you can perform operations on the databases.
Add a database
Click Add Database.
In the Bulk Authorize dialog box, enter the Database Name, Database Account, and Database Password, and then click OK.
NoteYou can enter multiple Database Name values.
Edit databases
Select the check boxes of one or more databases.
Click Bulk Authorize below the list.
In the Bulk Authorize dialog box, modify the Database Account and Database Password, and then click OK.
Cancel database connections
Select the check boxes of one or more databases.
Click Bulk Cancel below the list. Then, click OK.