Cisco Secure Access Help

PDF

Cisco Secure Access Help

Discovery Scan

Want to summarize with AI?

Log in

Describes Discovery Scan in Cisco Secure Access. Discovery Scan inspects the content of all files in the tenant that are modified over the selected date range.


Discovery Scan inspects the content of all files in the tenant that are modified over the selected date range. As files in the selected tenant are scanned upon content change and context (sharing) change, Secure Access assesses the file. If Secure Access detects a violation, the offending file is listed in the Data Loss Prevention Report.

This topic walks you through how to initiate a scan and how to cancel an ongoing scan.

Note
A discovery scan must be triggered around 24 hours after tenant authorization as the system evaluates and enumerates the users in the organization. Any triggering beforehand might not include all users. Secure Access performs discovery scans on files of up to 50 MB. For each file, the scan extracts up to the first 5 MB of plain text from the file, and scans that data for violations.

Prerequisites

  • You must authenticate a tenant for at least one of the platforms Secure Access supports for SaaS API Data Loss Prevention. For more information, see Manage SaaS API Data Loss Prevention.


Initiate a Discovery Scan

Procedure

  1. Navigate to Secure > Policy > Data Loss Prevention Policy.

  2. Click Discovery Scan.


    Data Loss Prevention Policy page with an option to start discovery scan
  3. Enter the Scan Details. Choose a platform and tenant of the platform from the drop-down lists.


    New Discovery scan page with fields for entering scan details
  4. Select where in uploaded files you would like the scan to search for the data classifications that you choose.

    • Content—(Default) Searches only the content of files for the selected data classifications.

    • File Name—Searches only file names for the selected data classifications.

    • Content and File Name—Searches content and file names for the selected data classifications. Both content and file name do not need to match for the scan to apply, only one or the other.

    Note
    Choosing Content, File Name, or Content and File Name refers to scanning file uploads for the selected data classifications and configured file labels.
  5. Select the required Data Classification of your choice. You can select multiple tenants.


    Data Classification page with options to select data classifications for the rule
  6. Enter the Date Range to define the scanning scope. Note that only files modified in the selected date range are scanned.


    Find Activity Date Range page with options to specify the data range
  7. Click Scan to initiate.

  8. Click Continue and Scan.

    Note
    Only one scan executes at a time. The scan might take a while. Once completed, you can initiate another scan.

    Discovery Scan page displaying scan duration information and an option to continue the scan
  9. Click Discovery Report to view the progress of the scan results.

    For more information on DLP reports, refer to DLP Report.


    Data Loss Prevention Policy page with an option to view the scan progress

Cancel a Discovery Scan

Procedure

  1. Navigate to Reporting > Additional Reports > Data Loss Prevention.

  2. Switch to the Discovery tab.


    Data Loss Prevention page displaying the Discovery tab
  3. Click Cancel Scan. Results of the ongoing scan are displayed in the ribbon.

    Note that the cancelation of a scan might take a few minutes.


    Discovery tab displaying ongoing scan results in a ribbon
  4. You can choose to either discard or keep the scan results and history. Click Cancel Scan.


    Cancel Discovery Scan page showing options to discard or keep the scan results and history, and cancel the scan