Onam Security

DSPM overview

DSPM in Onam Security: find every cloud data store, label it from metadata, and see how it is exposed, who reaches it and where its data flows.

Data security posture management answers three questions continuously rather than once before an audit: what data do we hold, where is it, and how exposed is it? Onam's DSPM runs inside every scan, alongside posture, identity and attack-path analysis, and writes its results onto the same security graph.

How DSPM works — data stores, discovery, metadata classification, the access and exposure join, findings
How DSPM works — data stores, discovery, metadata classification, the access and exposure join, findings

The five stages

StageWhat happensRead more
1. Data storesObject storage, managed databases and warehouses, streams, Kubernetes secrets and ConfigMaps, and self-hosted databases you onboardCoverage by cloud
2. DiscoverThe posture scan records each store and its settings: encryption, policies, ACLs, public-access block, logging, versioning, backup, region, relationshipsDiscovery
3. ClassifyNames, descriptions, tags, database and schema names become PII, PHI, PCI, financial and confidential labels. Contents are not readClassification
4. JoinPublic grants, cross-account grants, observed access, encryption and keys, attack pathsAccess mapping
5. FindingsPer store, every scan: classification, encryption, access, residency, logging, lifecycle, lineage and a 0–100 governance scoreFindings reference

What DSPM is, and is not

  • It is an always-current catalog of your data stores, with a sensitivity label you can trace to its source, and the exposure that makes each label matter.
  • It is metadata-based. It does not open objects, query rows, read stream messages or read secret values. Posture scanning connects through read-only cloud roles.
  • It is not a content scanner. A store whose name and tags say nothing about what it holds gets no label until someone tags it. See Classification and its limits.
  • It is not a DLP tool. It does not watch data in motion or block transfers.

How it connects to the rest of Onam

DSPM, Database Security and Encryption & Keys share one scan and answer different questions about the same data.

EngineQuestionWhat it takes from DSPMWhat it gives back
DSPMWhat data do we hold, where, how exposed?—Labels, exposure, lineage, governance score
Database SecurityIs each database hardened, private, audited, backed up?Labels on each databaseA sensitive database that is public or unencrypted is raised to critical
Encryption & KeysIs it encrypted with a key we control?Labels on each storeSensitive data unencrypted (critical) or on a provider-managed key (high)
Attack PathWhich chains of findings reach something valuable?Sensitive, public and unencrypted flags per storePaths that end at a sensitive store are scored as reaching a crown jewel
CIEMWho can do what?—Data-related identity findings merged into the DSPM view

Where to find it in the console

  • Data Security — the catalog, findings, residency and access-monitoring tabs.
  • Data Security → Lineage (/ui/datasec/lineage) — reconstructed chains with cross-region and cross-account hops flagged.
  • Database Security and Encryption — their own pages, with DSPM labels already applied.