Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Configure Classifications for Data Explorer

Organizations often have sensitive data that falls outside the scope of their primary DLP policies. Without a way to configure Expanded Scanning, you may miss hidden risks (like PII or SSNs) if their policies only target specific data types (like PCI). Conversely, scanning for everything can produce irrelevant results and lead to unnecessary storage costs.

The DSPM Scan Configuration allows you to granularly select which classifications are scanned for and displayed in the Data Explorer.

Key Benefits

  • Expanded Visibility. You can pick additional classifications to scan without modifying active DLP policies or generating additional SOC incidents.
  • Unified View. Data Explorer captures both primary (policy-based) and secondary (expanded) scan results.
  • Efficiency. Excludes scanning of irrelevant classifications and provides accurate results.
  • Safety Mechanism. A Config-In-Use check prevents the accidental deletion of classifications that are currently active in the Data Explorer configuration.

Use Cases

Use Case 1: Identify Shadow Sensitive Data Without Policy in Sanctioned Services

Context: An organization has strict DLP policies in place to monitor Financial Data (PCI) across their cloud storage to meet compliance audits. However, the SOC team suspects that employees may also be storing Personally Identifiable Information (PII), such as home addresses or passport numbers, which are not currently covered by any active policy.

Action: The admin uses the Data Explorer Configuration to add PII classifications to the Expanded Scan list.

Result: Skyhigh DSPM begins identifying PII in the same cloud repositories without the admin having to create new DLP policies or trigger thousands of new incidents in the policy incidents dashboard. The SOC team can now visualize the total footprint of PII in the Data Explorer to determine if a formal policy is needed later.

Use Case 2: Prevent Accidental Policy Gaps During Classification Cleanup

Context: A security admin is cleaning up old or redundant data classifications in the Skyhigh SSE console. They attempt to delete a custom classification labeled Internal Project - Skyhigh to simplify their workspace.

Action: The system performs an automated Config-In-Use check.

Result: Because Internal Project - Skyhigh is currently selected in the Data Explorer Scan Configuration for expanded visibility, the system blocks the deletion. This ensures that the organization does not accidentally lose visibility into critical project data that was being tracked outside of standard DLP policies.

Use Case 3: Optimize Scan Efficiency by Excluding Irrelevant Bulk Data

Context: A global enterprise uses a wide range of default classifications, including regional identifiers for countries where they no longer do business (e.g., specific European national IDs for a US-only project). These irrelevant classifications are causing noise in the Data Explorer and consuming unnecessary information.

Action: The admin navigates to the Classifications Page in the Data Explorer settings and removes the irrelevant regional classifications from the list.

Result: The DSPM is updated to ignore these specific classifications during the scans. This reduces redundant data storage and ensures that the Data Explorer dashboard remains focused only on the risks that matter to the organization’s current geographic scope, streamlining the risk assessment process.

Steps to Configure Classifications for Data Explorer


This section provides instructions to define which data classifications are scanned and made visible in your Data Explorer workspace.

NOTE: 

  • Skyhigh Security automatically scans your data against classifications defined in your active DLP policies.
  • Use this configuration to select additional classifications to be scanned that are not part of your current policies. This provides greater visibility into sensitive data without requiring policy modifications or generating additional SOC incidents.

 

 IMPORTANT: Use the Classification Configuration page to manage the classifications reported in Data Explorer. When you first access this page, Skyhigh Security automatically populates the list with classifications currently used in your DLP policies and a set of pre-determined standard classifications. 

After the initial population, you manually manage the configuration based on these requirements:

  • Manual Management. If you delete a classification from this list, it will no longer be reported in Data Explorer, even if it remains active in a policy.

  • New Classifications. When you create a new classification and reference it in a policy, you must manually add it to this page to ensure it is visible in Data Explorer.

To configure Classifications for Data Explorer:

  1. Log in to Skyhigh SSE and go to Analytics > DSPM Data Explorer.
  2. On the Data Explorer page, from the Data Explorer Settings drop-down, select Data Explorer Configuration.
    The Data Explorer Scan Configuration wizard opens.


     
  3. Complete the Services configuration (Step 1) and click Next.
  4. On the Classifications page (Step 2), view the list of classifications currently visible in Data Explorer.

  5. To add new classifications:

    1. Click + Add Classification.



      A Select Classifications side panel appears.

      clipboard_ee1c7756cb4a024fa804114fda565d8d3.png

    2. Search for classifications by keyword or browse by category (e.g., Finance & Trade, PII).
    3. Select the checkboxes for the classifications you want to include.
    4. Click Done in the Select Classifications side panel to add them to your list.
      This adds the classifications to the list.

      clipboard_e51e39b587402498d73a6a0431673746d.png
  6. (Optional) To remove a classification, click the X icon next to the classification name in the main list.

  7. (Optional) Click Reset to revert the list to the state it was in when you first navigated to this step.

  8. Click Next.
  9. On the Selection Summary page (Step 3), review your configuration:
  • Services Selected. Total count of services
  • Instances Selected. Total count of specific instances.
  • Classifications Selected. Total count of additional classifications to be scanned.

    clipboard_e01d1accfa083e62867cf7d1cf19a2f2e.png
  1. Click Save.
    This successfully saves the Classification configuration. The DSPM will apply these changes during the next scheduled data scan.

  2. (Optional) Click Edit to modify the selected Classifications or click Exit to leave the Data Explorer.

    clipboard_e82e8da66113b8486282812468c630a08.png

 

  • Was this article helpful?