Data Security Center (DSC) supports end-to-end management of sensitive data, from discovery and detection to governance and auditing. This topic describes how to purchase a subscription instance of a paid DSC edition.
Before you begin
Before you purchase Data Security Center (DSC), take note of the following information:
Limits — Limits apply to some regions and some types of data assets. For more information, see Supported regions.
Free trial — DSC provides a Free Edition. To try out or evaluate the features before you purchase a paid edition, activate the Free Edition or the .
Compare paid editions
The following table compares the target scenarios and the base-price specifications of the paid DSC editions. Start from the base-price specifications: check whether the included quotas cover the scale of the data assets that you want to protect, whether you need Data Detection and Response, and whether you must meet MLPS compliance requirements. For a detailed edition comparison and billing information, see Edition comparison and Billing.
Item | Advanced Edition | Enterprise Edition | Value-added Plan | Database Auditing (MLPS-compliant Edition) |
Scenarios | Designed for small customers. Provides basic security protection and supports only small-scale data identification and data auditing. | Designed for small and medium-sized enterprises that must meet data security and compliance requirements. | Lets you purchase individual value-added service capabilities on demand. Suitable for customized purchasing requirements in large-scale business scenarios. | Designed for MLPS compliance requirements. Replaces the legacy database auditing edition and supports data auditing for multiple data types, including databases, Object Storage Service (OSS), and big data. |
Features included in the base price | Data Identification: 1 TB of storage for identification, 10,000 database tables; Data Auditing: 1 TB of storage, 1 database instance; Column Encryption: 1 column; Log Storage Capacity: 250 GB | Data Identification: 3 TB of storage for identification, 30,000 database tables; Data Auditing: 3 TB of storage, 3 database instances; Data Detection and Response: 3 TB of storage, 3 database instances; Image Masking: 10,000 images; Column Encryption: 10 columns; Log Storage Capacity: 1,500 GB | Not included | Data Auditing: 1 TB of storage, 3 database instances; Log Storage Capacity: 650 GB |
Additional paid feature extensions | All features can be enabled or have their quotas extended for an additional fee. | See the parameter table for this edition in Feature extension parameters. | See the parameter table for this edition in Feature extension parameters. | See the parameter table for this edition in Feature extension parameters. |
Quota rules and limits
The following rules determine how quickly your DSC quotas are consumed and which inputs are excluded from detection. Review them before you decide which quotas to purchase.
Repeated scans consume quota per scan — If the same data asset is scanned multiple times, the consumed Data Identification quota is calculated based on the actual number of scans. For example, if a single table is scanned three times, the quota for three database tables is deducted.
Repeated masking consumes quota per operation — A single image may be masked multiple times and consume multiple Image Masking quota units.
Column Encryption depends on Data Identification — Column Encryption relies on the sensitive data identification capability of Data Identification. Purchase a sufficient Data Identification quota.
Default log storage — DSC includes 200 GB of log storage for each authorized database instance and 50 GB for every 1 TB of authorized OSS protection. If the default storage is insufficient, extend the Log Storage Capacity quota when you place your order.
Reserve enough log storage space. When the log storage space is exhausted, new logs for the asset are no longer stored, which results in log loss.
Feature extension parameters
The following tables describe the parameters that you can configure on the buy page to enable additional features or to extend quotas beyond the base specifications of an edition. Use the table for the edition that you want to purchase.
Advanced Edition or Enterprise Edition
Parameter | Description |
Data Detection and Response | Enables Data Detection and Response to discover and handle security events such as leaks of database credentials and AccessKey pairs. You can then specify Data Detection and Response - OSS Protection Capacity and Data Detection and Response - Number of Database Instances to extend the protection quota. |
Data Auditing | Enables Data Auditing to collect logs and generate alerts for attacks and anomalous operations. You can then specify Data Auditing - OSS Protection Capacity and Data Auditing - Number of Database Instances to extend the audit quota. |
Data Identification | Enables Data Identification to identify sensitive data and classify and grade it. You can then specify Data Identification - Database Table Quantity and Data Identification - Storage Identification Capacity to extend the identification quota. |
Image Masking | Enables Image Masking. You can then specify Image Masking Count to extend the quota. |
Column Encryption | Enables Column Encryption to encrypt sensitive information columns in databases. You can then specify Columns (unit: columns) to extend the quota. |
Log Storage Capacity | If the default log storage is insufficient, enable this option and select Log Storage Capacity to extend the quota. |
Value-added Plan
Parameter | Description |
Data Detection and Response | Enables Data Detection and Response to discover and handle security events such as leaks of database credentials and AccessKey pairs. You can then specify the Data Detection and Response - OSS Protection Capacity and Data Detection and Response - Number of Database Instances protection quotas. |
Data Auditing | Enables Data Auditing to collect logs and generate alerts for attacks and anomalous operations. You can then specify the Data Auditing - OSS Protection Capacity and Data Auditing - Number of Database Instances audit quotas. |
Data Identification | Enables Data Identification to identify sensitive data and classify and grade it. You can then specify the Data Identification - Database Table Quantity and Data Identification - Storage Identification Capacity quotas. |
Image Masking | Enables Image Masking. You can then specify the Image Masking Count quota. |
Column Encryption | Enables Column Encryption to encrypt sensitive information columns in databases. You can then specify the Columns (unit: columns) quota. |
Log Storage Capacity | If the default log storage is insufficient, enable this option and select Log Storage Capacity to extend the quota. |
Database Auditing (MLPS-compliant Edition)
Parameter | Description |
Data Auditing | Enables Data Auditing to collect logs and generate alerts for attacks and anomalous operations. You can then specify Data Auditing - OSS Protection Capacity and Data Auditing - Number of Database Instances to extend the audit quota. |
Log Storage Capacity | If the default log storage is insufficient, enable this option and select Log Storage Capacity to extend the quota. |
Purchase a paid edition
Go to the DSC buy page.
In the version section, select the edition that you want to purchase, and then specify Duration for the subscription. Renew the instance before it expires to avoid business impact. (Recommended) Select . After you enable this option, the system automatically renews the DSC instance on the day it expires.
(Optional) To extend features beyond the specifications of the edition, configure the extension parameters for the edition that you selected. For parameter descriptions, see Feature extension parameters. If the base specifications meet your requirements, skip the extension parameters.
Click Buy Now and complete the payment.
Next steps
After you purchase DSC, get started with the following steps:
Authorize your assets in Asset Center. For instructions, see Asset Center (New).
Configure the following features based on your business scenarios:
Classification and Grading (Recommended): Identifies sensitive information and grades it.
Configuration Risk (Recommended): Identifies configuration risks on the Alibaba Cloud platform.
Column Encryption: Encrypts sensitive information columns in databases. Unauthorized personnel can read only the ciphertext.
Image Masking: Masks sensitive information in images in OSS buckets.
Data Detection and Response: Discovers and handles security events such as leaks of database credentials and AccessKey pairs.
Data Auditing: Enables cloud-native log collection and generates alerts for attacks and anomalous operations.