All Products
Search
Document Center

Object Storage Service:Check the security configuration compliance of a bucket

Last Updated:Mar 20, 2026

Data Security Center (DSC) evaluates whether your OSS buckets meet security configuration standards — covering access control, encryption, logging, versioning, and transmission security. When a check fails, DSC pinpoints the risk and links you directly to the setting that needs fixing.

Check items covered

DSC runs baseline security checks against the Alibaba Cloud Data Security Best Practices policy. The following check items apply to OSS buckets:

Policy categoryCheck itemWhat it checks
Data storage securityOSS-enable Bucket server-side encryptionWhether server-side encryption is enabled
Data backup and recoveryOSS-enable Bucket version controlWhether versioning is enabled
Access control managementOSS-configure an access source IP address whitelistWhether the bucket is publicly exposed
Data transmission encryptionOSS-enable secure encrypted transmissionWhether encryption in transit is enabled for objects
Log monitoring auditOSS-enable log storageWhether log storage is enabled
Identity rights managementOSS-anonymous account "read/write/full control" permission configurationWhether public-read-write permissions are configured
Sensitive data protectionOSS-log file public read (write) access permission settings; OSS-sensitive data Bucket public read (write) Access CheckWhether log files or sensitive data are publicly readable or writable

The end-to-end workflow consists of four steps:

  1. Create an OSS bucket

  2. Add the OSS bucket to DSC

  3. Manually run a baseline security check

  4. View and handle security risks

Prerequisites

Before you begin, ensure that you have:

Step 1: Create an OSS bucket

  1. In the OSS console, go to the Buckets page and click Create Bucket.

  2. In the Create Bucket panel, configure the required parameters, keep the default settings for the remaining parameters, and click Create.

image

Step 2: Add the OSS bucket to DSC

  1. Log on to the Data Security Center console.

  2. In the left navigation pane, click Asset Center.

  3. In the Unstructured Data area, click OSS, and then click Asset synchronization.

    image

  4. After synchronization completes, find the newly created bucket and turn on the Configuration Risks switch. Wait for the Connection Status to change to Connected.

    image

Step 3: Manually run a baseline security check

DSC runs a baseline check on connected assets at approximately 01:00 every day. To view results immediately, run the check manually.

View and confirm the check policy

  1. In the left navigation pane, choose Risk Governance > Configuration Risks.

  2. On the Policies > Alibaba Cloud Data Security Best Practices tab, review the OSS-related check items and their status.

    Note

    The PIPL Security Baseline requires an Enterprise instance of DSC. This example uses Alibaba Cloud Data Security Best Practices, which is available in the Free Edition.

    By default, DSC enables all check items in the baseline check policy.

    image

  3. Confirm that the status column for each OSS check item shows the enabled icon image.

Run security checks manually

  1. On the Risk Trends > Alerts tab, find the target policy and click Details in the Actions column.

  2. On the Risk Situation tab, click Check for each OSS check item. The check is complete when the Check button becomes active again. Close the panel.

    image

  3. Repeat the preceding steps for each check policy.

Step 4: View and handle security risks

View check results for the bucket

  1. On the Asset Risks tab, search for the target bucket to view check results. The detection time shows when the last check ran.

    image

  2. Click Handle in the Actions column to see which check items failed and their recommended fixes.

    image

Fix risk items

  1. In the Risk Details area, click Handle next to a risk item. DSC redirects you to the relevant configuration page. For example, to fix OSS-enable Bucket server-side encryption: on the Server-side Encryption page, click Settings, select OSS-Managed as the encryption method, and click Save. For full configuration details, see Server-side encryption.

    image

Verify the fix

Return to the risk details panel in DSC and click Recheck.

image

A passed status confirms the risk item is resolved.

image

Repeat this process for all remaining risk items.

What's next

Sensitive data protection

By default, OSS-sensitive data Bucket public read (write) Access Check passes for any bucket where sensitive data has not yet been detected. After you store data in the bucket, create a sensitive data detection task to periodically scan for sensitive data. If sensitive data is found, DSC runs this check item automatically so you can address any access control risks.

For more information, see Scan for sensitive data using a detection task.

Important

The Free Edition of Data Security Center provides 5 GB of free OSS data detection per month. For higher volumes, purchase a paid instance. For more information, see Purchase DSC.

Whitelist management

If a failed check result for a specific asset can be safely ignored, go to the Asset Risks tab, find the asset, and click Add to Whitelist in the Actions column.

image
Important

The Free Edition of Data Security Center does not support whitelist management. An Enterprise instance is required.