建立 Sensitive Data Protection 檢查範本

本主題將詳細說明如何建立新的檢查範本。如需使用Google Cloud 控制台建立新檢查範本的快速逐步操作說明,請參閱快速入門:建立 Sensitive Data Protection 檢查範本

關於範本

您可以使用「範本」建立及保留設定資訊,以便與 Sensitive Data Protection 搭配使用。範本很適合用於將檢查內容和去識別化方式等設定資訊與要求的實作分離,範本不僅可以讓您重複使用設定,也能保持使用者和資料集之間的一致性。此外,更新範本時,系統也會更新使用該範本的所有工作觸發條件。

Sensitive Data Protection 可支援本主題中討論到的檢查範本,也可支援建立 Sensitive Data Protection 去識別化範本一文中討論的去識別化範本。

如要瞭解 Sensitive Data Protection 範本的概念資訊,請參閱範本一文。

如要進一步瞭解可在檢查範本中指定的資訊類型 (infoTypes),請參閱 InfoType 偵測工具參考資料

建立新的檢查範本

控制台

前往 Google Cloud 控制台的「建立範本」頁面。

前往「建立範本」

「建立範本」頁面包含下列區段:

定義範本

在「定義範本」下方,輸入檢查範本的 ID。在執行工作、建立工作觸發條件和進行其他作業時,您必須以此名稱參照這個範本。您可以使用英文字母、數字和連字號。您也可以視需要輸入更貼近人性的顯示名稱,以及一段說明,方便記住範本的用途。

在「資源位置」欄位中,選取要檢查的資料儲存所在區域。您建立的檢查範本也會儲存在這個區域。如要在任何區域使用新的檢查範本,請選取「Global (any region)」(全域 (任何區域))

設定偵測作業

接著,請選擇 infoType 和其他選項,設定 Sensitive Data Protection 要在內容中偵測的項目。

InfoType 偵測工具可尋找特定類型的機密資料。例如,Sensitive Data Protection US_SOCIAL_SECURITY_NUMBER infoType 偵測工具可尋找美國社會安全號碼。除了內建的 infoType 偵測工具,您也可以建立自己的自訂 infoType 偵測工具。

在「InfoTypes」(infoType)InfoTypes 專區中,根據您要掃描的資料類型,選擇對應的 infoType 偵測工具。我們不建議將這個部分留空。這麼做會導致 Sensitive Data Protection 使用預設的 infoType 組合掃描資料,其中可能包含您不需要的 infoType。InfoType 偵測工具參考資料中提供每個偵測工具的詳細資訊。

如要進一步瞭解如何管理這個專區中的內建和自訂 infoType,請參閱透過 Google Cloud 管理控制台管理 infoType

檢查規則集

檢查規則集可讓您使用內容規則,自訂內建和自訂的 infoType 偵測工具。檢查規則類型包括:

  • 排除規則:可協助排除誤判或不需要的發現項目。
  • 啟動字詞規則:可協助偵測更多的發現項目。
  • 調整規則:根據發現項目出現的前後文,調整發現項目的可能性。

如要新增規則集,請先在「InfoTypes」InfoTypes部分指定一或多個內建或自訂 infoType 偵測工具。選取規則集修改的所有 infoType 偵測工具 (target infoType),或用於評估的偵測工具 (context infoType)。然後執行下列步驟:

  1. 按一下「新增規則集」
  2. 在「選擇目標 infoType」欄位中,選取規則集在符合規則時要修改的 infoType。
  3. 按一下「新增規則」,開啟含有選項的選單,包括「啟動字詞規則」、「排除規則」和「調整規則」

如要建立啟動字詞規則,請選取「啟動字詞規則」。然後執行下列步驟:

  1. 在「Hotword」(熱字) 欄位中,輸入 Sensitive Data Protection 要搜尋的規則運算式。
  2. 在「啟動字詞鄰近程度」選單中,選取輸入的啟動字詞是在所選 infoType 之前或之後。
  3. 在「啟動字詞與 infoType 的距離」中,輸入啟動字詞和所選 infoType 之間的約略字元數。
  4. 在「信賴水準調整」中,選取要為相符項目指派固定可能性等級,還是要將預設可能性等級調高或調低特定幅度。

如要建立排除規則,請選取「排除規則」和要建立的排除規則類型,例如「規則運算式」。然後執行下列步驟:

  1. 根據您選取的排除規則類型,輸入規則運算式、詞組、啟動字詞或結構定義 infoType,系統必須找到這些項目才能套用規則。
  2. 視您選取的排除規則類型而定,設定相符類型或圖片包含類型:
    • 如果您選取以文字為準的排除規則,請選取下列其中一種比對類型:
      • 完全比對:發現項目必須與您提供的文字或脈絡資訊 infoType 完全相符。
      • 部分相符:發現項目的子字串必須與您提供的文字或脈絡資訊 infoType 相符。
      • 反向比對:發現項目不得與您提供的文字或脈絡資訊 infoType 相符。
    • 如果您選取以圖片為準的排除規則,請選取目標和內容 infoType 之間的必要空間關係。舉例來說,如果您選取「Encloses」(封閉),則情境發現項目必須封閉目標發現項目,規則才會套用。

如要建立調整規則,請選取「調整規則」和調整規則類型,例如「依圖片結果調整」。然後執行下列步驟:

  1. 在「Context infoTypes」欄位中,選取可為目標發現項目提供脈絡的 infoType 偵測工具。Sensitive Data Protection 會使用背景資訊類型,評估是否需要調整目標資訊類型。
  2. 在「最低可能性」欄位中,選取內容 infoType 的最低可能性等級,只要達到這個等級,就會觸發調整規則。如果偵測到的任何內容發現項目的可能性值低於這個值,Sensitive Data Protection 就不會調整目標發現項目的可能性。
  3. 如果是圖片結果,請在「圖片包含類型」欄位中,選取目標和內容資訊類型之間所需的空間關係。舉例來說,如果您選取「Encloses」(封閉),則情境發現項目必須封閉目標發現項目,規則才會套用。
  4. 在「可能性」欄位中,選取要指派給目標發現項目的新可能性等級。

您可以新增更多規則集,進一步縮小掃描結果範圍。

可信度門檻

每當 Sensitive Data Protection 偵測到可能符合的私密資料時,系統會根據「極不可能」到「極有可能」的範圍,為該資料指派「可能性」值。在此設定可能性值時,您是在指示 Sensitive Data Protection 只比對符合該可能性值或更高的資料。

預設值「Possible」(或許可能) 足以供大多數情況使用。如果您經常得到過於寬泛的相符項目,請將滑桿上移。如果您得到的相符項目太少,請將滑桿下移。

完成之後,按一下 [Create] (建立) 即可建立範本。系統隨即會顯示範本的摘要資訊頁面。

如要返回 Sensitive Data Protection 主頁面,請在 Google Cloud 控制台中按一下「返回」箭頭。

C#

如要瞭解如何安裝及使用 Sensitive Data Protection 的用戶端程式庫,請參閱「Sensitive Data Protection 用戶端程式庫」。

如要向 Sensitive Data Protection 進行驗證,請設定應用程式預設憑證。詳情請參閱「為本機開發環境設定驗證機制」。


using Google.Api.Gax.ResourceNames;
using Google.Cloud.Dlp.V2;
using System;

public class InspectTemplateCreate
{
    public static InspectTemplate Create(
        string projectId,
        string templateId,
        string displayName,
        string description,
        Likelihood likelihood,
        int maxFindings,
        bool includeQuote)
    {
        var client = DlpServiceClient.Create();

        var request = new CreateInspectTemplateRequest
        {
            Parent = new LocationName(projectId, "global").ToString(),
            InspectTemplate = new InspectTemplate
            {
                DisplayName = displayName,
                Description = description,
                InspectConfig = new InspectConfig
                {
                    MinLikelihood = likelihood,
                    Limits = new InspectConfig.Types.FindingLimits
                    {
                        MaxFindingsPerRequest = maxFindings
                    },
                    IncludeQuote = includeQuote
                },
            },
            TemplateId = templateId
        };

        var response = client.CreateInspectTemplate(request);

        Console.WriteLine($"Successfully created template {response.Name}.");

        return response;
    }
}

Go

如要瞭解如何安裝及使用 Sensitive Data Protection 的用戶端程式庫,請參閱「Sensitive Data Protection 用戶端程式庫」。

如要向 Sensitive Data Protection 進行驗證,請設定應用程式預設憑證。詳情請參閱「為本機開發環境設定驗證機制」。

import (
	"context"
	"fmt"
	"io"

	dlp "cloud.google.com/go/dlp/apiv2"
	"cloud.google.com/go/dlp/apiv2/dlppb"
)

// createInspectTemplate creates a template with the given configuration.
func createInspectTemplate(w io.Writer, projectID string, templateID, displayName, description string, infoTypeNames []string) error {
	// projectID := "my-project-id"
	// templateID := "my-template"
	// displayName := "My Template"
	// description := "My template description"
	// infoTypeNames := []string{"US_SOCIAL_SECURITY_NUMBER"}

	ctx := context.Background()

	client, err := dlp.NewClient(ctx)
	if err != nil {
		return fmt.Errorf("dlp.NewClient: %w", err)
	}
	defer client.Close()

	// Convert the info type strings to a list of InfoTypes.
	var infoTypes []*dlppb.InfoType
	for _, it := range infoTypeNames {
		infoTypes = append(infoTypes, &dlppb.InfoType{Name: it})
	}

	// Create a configured request.
	req := &dlppb.CreateInspectTemplateRequest{
		Parent:     fmt.Sprintf("projects/%s/locations/global", projectID),
		TemplateId: templateID,
		InspectTemplate: &dlppb.InspectTemplate{
			DisplayName: displayName,
			Description: description,
			InspectConfig: &dlppb.InspectConfig{
				InfoTypes:     infoTypes,
				MinLikelihood: dlppb.Likelihood_POSSIBLE,
				Limits: &dlppb.InspectConfig_FindingLimits{
					MaxFindingsPerRequest: 10,
				},
			},
		},
	}
	// Send the request.
	resp, err := client.CreateInspectTemplate(ctx, req)
	if err != nil {
		return fmt.Errorf("CreateInspectTemplate: %w", err)
	}
	// Print the result.
	fmt.Fprintf(w, "Successfully created inspect template: %v", resp.GetName())
	return nil
}

Java

如要瞭解如何安裝及使用 Sensitive Data Protection 的用戶端程式庫,請參閱「Sensitive Data Protection 用戶端程式庫」。

如要向 Sensitive Data Protection 進行驗證,請設定應用程式預設憑證。詳情請參閱「為本機開發環境設定驗證機制」。


import com.google.cloud.dlp.v2.DlpServiceClient;
import com.google.privacy.dlp.v2.CreateInspectTemplateRequest;
import com.google.privacy.dlp.v2.InfoType;
import com.google.privacy.dlp.v2.InspectConfig;
import com.google.privacy.dlp.v2.InspectTemplate;
import com.google.privacy.dlp.v2.LocationName;
import java.io.IOException;
import java.util.List;
import java.util.stream.Collectors;
import java.util.stream.Stream;

class TemplatesCreate {