이제 Cloud Data Loss Prevention(Cloud DLP)은 민감한 정보 보호에 포함됩니다. API 이름은 Cloud Data Loss Prevention API(DLP API)로 그대로 유지됩니다. 민감한 정보 보호를 구성하는 서비스에 대한 자세한 내용은 민감한 정보 보호 개요를 참조하세요.
이 페이지에서는 Sensitive Data Protection에서 데이터 프로필에 할당하는 데이터 위험 및 민감도 수준을 설명합니다. 데이터 위험 수준을 이해하려면 먼저 민감도 수준을 이해해야 합니다.
민감도 수준
민감도 수준은 프로젝트, 테이블 또는 파일 스토어에 있는 데이터가 얼마나 민감한지 나타냅니다. 개인 식별 정보 (PII), 금융 데이터, 사용자 인증 정보와 같이 감지된 요소가 포함된 데이터는 민감합니다.
검사할 각 기본 제공 또는 맞춤 infoType의 민감도를 설정할 수도 있습니다. 감지된 각 infoType의 민감도는 프로파일링된 리소스의 결과 민감도 등급에 영향을 미칩니다. 기본 제공 infoType의 민감도를 재정의하거나 커스텀 infoType의 민감도를 설정하는 방법에 관한 자세한 내용은 infoType 관리를 참고하세요.
[[["이해하기 쉬움","easyToUnderstand","thumb-up"],["문제가 해결됨","solvedMyProblem","thumb-up"],["기타","otherUp","thumb-up"]],[["이해하기 어려움","hardToUnderstand","thumb-down"],["잘못된 정보 또는 샘플 코드","incorrectInformationOrSampleCode","thumb-down"],["필요한 정보/샘플이 없음","missingTheInformationSamplesINeed","thumb-down"],["번역 문제","translationIssue","thumb-down"],["기타","otherDown","thumb-down"]],["최종 업데이트: 2025-09-04(UTC)"],[],[],null,["# Sensitivity and data risk levels\n\nThis page describes the data risk and sensitivity levels that Sensitive Data Protection\nassigns to [data profiles](/sensitive-data-protection/docs/data-profiles). To\nunderstand the data risk levels, it's important to understand the sensitivity\nlevels first.\n| **Note:** When generating data profiles, Sensitive Data Protection scans for only the infoTypes that you specify in your [inspection template](/sensitive-data-protection/docs/data-profiles#inspection-template). For example, suppose credit card numbers are present in a column. If the `CREDIT_CARD_NUMBER` infoType isn't listed in your inspection template, then the resulting sensitivity and data risk levels for that column don't reflect the presence of credit card numbers.\n\nSensitivity level\n-----------------\n\n*Sensitivity level* is an indication of how sensitive the data in a project,\ntable, or file store is. Data is sensitive if it contains detected elements,\nsuch as personally identifiable information (PII), financial\ndata, and credentials.\n\nYou can also set the sensitivity of each built-in or custom infoType that you\nscan for. The sensitivity of each detected infoType affects the resulting\nsensitivity rating of the profiled resource. For information about how to\noverride the sensitivity of a built-in infoType or set the sensitivity of a\ncustom infoType,\nsee [Manage infoTypes](/sensitive-data-protection/docs/manage-infotypes-console).\n\nA data profile can have any of the following sensitivity levels:\n\nHigh\n: [Highly sensitive information](/sensitive-data-protection/docs/high-sensitivity-infotypes-reference)\n might be present, including credit card numbers and certain national identifiers.\n\nModerate\n: Sensitive information that is not classified as highly sensitive might be\n present. Examples are email addresses and phone numbers, which can be considered\n personally identifiable. The data might also include freeform text or\n unstructured data, such as comments.\n\nLow\n: Sensitive information wasn't detected, and the data doesn't include freeform\n text or unstructured data.\n\nUnknown\n: The data couldn't be scanned successfully. It is uncertain if sensitive data exists.\n\n### Sensitivity signals\n\nTo calculate sensitivity, Sensitive Data Protection considers the following:\n\n- Both the default sensitivity of each infoType found along with any user overrides of the sensitivity.\n- The [likelihood](/sensitive-data-protection/docs/likelihood) that [highly sensitive infoTypes](/sensitive-data-protection/docs/high-sensitivity-infotypes-reference) are present.\n- Whether the data has an unstructured format and contains mostly freeform text, like comments.\n\nData risk level\n---------------\n\n*Data risk level* is the risk associated with the data in its current state. It\nconsiders the sensitivity level of the data in the resource and the presence of\naccess controls to protect that data.\n\nHigh\n: [High-sensitivity data](/sensitive-data-protection/docs/sensitivity-risk-calculation#high-sensitivity)\n might be present, and there are no access controls to restrict data\n exposure. Alternatively, moderate or high-sensitivity data is widely accessible.\n\nModerate\n: [Moderate-sensitivity data](/sensitive-data-protection/docs/sensitivity-risk-calculation#moderate-sensitivity)\n might be present, and there are no access controls to restrict data\n exposure.\n\nLow\n\n: The sensitivity level of the data is low. Alternatively, access to the data\n has been further restricted, for example, through access controls.\n\n A profiled data asset can also get a `Low` data risk level if you [enabled\n automatic\n tagging](/sensitive-data-protection/docs/control-access-based-on-data-sensitivity#enable-automatic-tagging-discovery)\n and opted to automatically set the data risk of the profiled data assets to\n `Low`.\n\nUnknown\n\n: The data couldn't be scanned successfully. It is uncertain if sensitive data exists.\n\n### Data risk signals\n\nTo calculate data risk, Sensitive Data Protection considers the following:\n\n- The calculated sensitivity level of the data.\n- The presence of access controls that limit access to the data.\n- Whether discovery is configured to set the data risk level to `Low` when automatic tagging is enabled. For more information, see [Enable the automatic\n tagging in the discovery\n configuration](/sensitive-data-protection/docs/control-access-based-on-data-sensitivity#enable-automatic-tagging-discovery). This option automatically overrides any of the storage-specific formulas.\n\n### BigQuery data risk calculation\n\nThe following table shows how [data risk signals](#data_risk_calculation) affect\nthe resulting data risk level that Sensitive Data Protection assigns to profiled\nBigQuery resources. The **Data risk** column shows the resulting data\nrisk level.\n\n### Cloud SQL data risk calculation\n\nThe following table shows how [data risk signals](#data_risk_calculation) affect\nthe resulting data risk level that Sensitive Data Protection assigns to profiled\nCloud SQL resources. The **Data risk** column shows the resulting data risk\nlevel.\n\n### File store data risk calculation\n\nThe following table shows how [data risk signals](#data_risk_calculation) affect\nthe resulting data risk level that Sensitive Data Protection assigns to profiled\nfile store resources. The **Data risk** column shows the resulting data risk\nlevel.\n\nWhat's next\n-----------\n\n- Learn about [remediations](/sensitive-data-protection/docs/data-profiles-remediation) you can take to reduce data risk and sensitivity."]]