Create the Scan
Objective: Create a DLP Scan
Here you’ll notice that creating an on-demand scan for the EDM-based policies is exactly the same as it was for regular expressions and Skyhigh classifications.
Tasks
Create a Scan
- From the main menu bar, select Policy then On-Demand Scan.
- Using the Actions drop-down menu, select Create a Scan.
- From the General Info screen, select the DLP & Malware scan type.
- Provide a name for the scan, such as “EDM DLP Scan”.
- Under the Service Instance dropdown, select the AWS account you configured earlier.
- For Service Type select Storage (S3).
- For Hosted select Cloud (via API).
- Click Next.
Add all your cloned/customized policies to the scan
- From the Select Policies page, select the EDM-based DLP policy you just created.
- Click Next.
Configure the Scan
- From the Data Scope section, select the Full option and All dates.
- In the Buckets section, select the Exclude CloudTrail Buckets option (if available) and set Buckets to Scan to All Buckets.
- In the Accounts section, set Accounts to Scan to All Accounts.
- Click Next.
(Don’t) Schedule the Scan
- Since we are in a lab environment and want to run this scan manually, set the Frequency to None (On-Demand Only).
- Click Next.
Review Your Scan Settings
Ensure that your scan settings are what you intend and click Save.