Cloud Storage Security Help Docs
Release Notes
  • Introduction
  • Getting Started
    • How to Subscribe
      • Pay-As-You-Go (PAYG)
      • Bring Your Own License/GovCloud (BYOL)
      • AWS Transfer Family
    • How to Deploy
      • Steps to Deploy
      • Advanced Deployment Considerations
      • AWS Transfer Family
    • How to Configure
  • Console Overview
    • Dashboard
    • Malware Scanning
      • AWS
        • Buckets
        • Amazon EBS Volumes
        • Amazon EFS Volumes
        • Amazon FSx Volumes
        • WorkDocs Connections
      • Azure
        • Blob Containers
      • GCP
        • GCP Buckets
    • See What's Infected
      • Findings
      • Malware History
      • Results
    • Schedules
    • Monitoring
      • Error Logs
      • Bucket Settings
      • Deployment
      • Jobs
      • Notifications
      • Storage Assessment
      • Usage
    • Configuration
      • Classification Rule Sets
      • Classification Custom Rules
      • Scan Settings
      • Console Settings
      • AWS Integrations
      • Job Networking
      • API Agent Settings
      • Proactive Notifications
      • License Management
      • Event Agent Settings
    • Access Management
      • Manage Users
      • Manage Accounts
        • Linking an AWS Account
        • Linking an Azure Account
        • Linking a GCP Account
      • Manage Groups
    • Support
      • Getting Started
      • Stay Connected
      • Contact Us
      • Documentation
  • Product Updates
  • How It Works
    • Scanning Overview
      • Event Driven Scanning for New Files
      • Retro Scanning for Pre-Existing Files
      • API Driven Scanning
    • Architecture Overview
    • Deployment Details
    • Sizing Discussion
    • Integrations
      • AWS Security Hub
      • AWS CloudTrail Lake
      • AWS Transfer Family
      • Amazon GuardDuty
      • Amazon Bedrock
    • Demo Videos
    • Scanning APIs
    • SSO Integrations
      • Entra ID SSO Integration
      • Okta SSO Integration
  • Frequently Asked Questions
    • Getting Started
    • Product Functionality
    • Architecture Related
    • Supported File Types
  • Troubleshooting
    • CloudFormation Stack failures
    • Cross-Region Scanning on with private network
    • API Scanning: Could not connect to SSL/TLS (v7)
    • Password not received after deployment
    • Conflicted buckets
    • Modifying scaling info post-deployment
    • Objects show unscannable with access denied
    • Remote account objects not scanning
    • My scanning agents keep starting up and immediately shutting down
    • I cannot access the management console
    • Linked Account Out of Date
    • Rebooting the Management Console
    • Error when upgrading to the latest major version
    • I Cannot Create/Delete an API Agent
  • Release Notes
    • Latest (v8)
    • v7
    • v6 and older
  • Contact Us & Support
  • Data Processing Agreement
  • Privacy Policy
Powered by GitBook
On this page
  • Creating a custom rule set
  • Rule Locales
  • Default Rule Sets
  1. Console Overview
  2. Configuration

Classification Rule Sets

If you have Data Classification enabled you will see this Classification Rule Sets page under the Configuration section

PreviousConfigurationNextClassification Custom Rules

Last updated 5 months ago

Here you will see the rule sets available for Data Classification. The grey rule sets are default rule sets available out of the box. You cannot edit these default rule sets.

The Rules Count column will show how many rules exist in each rule set. The Containers Count column shows how many buckets a particular rule set is enabled on whether it be for event-based or retro-based data classification.

Creating a custom rule set

You can create your own custom rule set by clicking the Create Rule Set button. A custom rule set will allow you to mix and match rules from any default rule set available. This way you can build a rule set based on the specific frameworks and data you need to classify on.

Once you have the rules selected for your custom rule set you can click the save button to create the rule set. After that all you need to do is enable event-based protection on a bucket or create a DC schedule.

Rule Locales

You'll notice that some rules can be global since the type of information that is being classified isn't formatted in a specific way. Other rules can have localized options since the type of information you need to classify on can be different based on country.

Filtering Locales

You can filter the rule sets down to show only rules for specific countries. Select the country you want to filter by from the Regions dropdown.

Default Rule Sets

Below is a list of the default rule sets we currently have available, the number of rules for each rule set, and descriptions of what you can expect for each rule set.

Rule Set
Number of Rules
Description

Canadian Health Service

9

Personal health card number information for British Columbia, Ontario, and Quebec.

Document classification

33

Confidential, sensitive, personal, etc. content markers

Financial Data

87

Bank account details, credit card numbers, financial/personal identifiers, etc.

Health Care

26

Social Security Numbers, ailments, medical patient forms, etc.

HIPAA

15

Social Security Numbers, ailments, medical patient forms, etc. Localized to USA formats and specific for HIPAA compliance

Item identifiers

13

Vehicle license plates, Postal codes, Microsoft license keys, etc.

PCI DSS

55

Bank account details, credit card numbers, financial/personal identifiers, etc. Specific to PCI DSS compliance

Personally Identifiable Information

319

Bank account details, driver's license details, passport details, etc.

UK National Health Service

5

National insurance numbers with qualifying term, National insurance numbers, NHS number personal identifier near date of birth, NHS number personal identifier, Community Health Index. Specific rule set for the United Kingdom

Additionally, you can add your own you've created as part of this custom rule set.

custom classification rules
Rule Sets Page
Select your rules
Select either the entire rule or a specific country in the list
Search for a specific locale in the Regions dropdown