DataSec Command Center (DCC) is a Netskope capability that provides unified visibility, risk assessment, and remediation for data security across your organization. As sensitive data spreads across SaaS applications, IaaS environments, and on-premises infrastructure, DCC enables security teams to:
- Discover and monitor sensitive data across connected data stores and inline destinations.
- Assess data security risks through predefined risk policies.
- Remediate findings through retroactive scans, ongoing policies, or real-time protection rules.
Supported Products
DataSec Command Center consolidates signals from three Netskope products:
- CASB API: Provides visibility into SaaS application data stores through API-based connections. To surface CASB API data in DCC, enable DSPM for each app instance in your tenant.
- DSPM: Provides visibility into sensitive data and its risks across IaaS, PaaS, SaaS, and on-premises data stores through discovery and ongoing scans.
- Real-Time Protection (Inline): Provides visibility into data in motion through inline traffic inspection.
To learn more about connecting data stores for CASB API and DSPM: Connecting Data Stores
DataSec Command Center works with any combination of these products. The features and data available depend on which products you license and configure.
Key Concepts
To successfully navigate DataSec Command Center, familiarize yourself with the following foundational terms:
| Concept | Definition |
|---|---|
| Stored Data (Data at Rest) | Data residing in connected data stores, scanned through DSPM. |
| Transfered Data (Data in Motion) | Data uploaded or downloaded, detected through Real-Time Protection. |
| Data Types | Predefined DLP entity classifications of sensitive data (e.g., personal name, payment card, email address). Each data type maps to one data category. To learn more: Configure Entity Data Types and Sensitivity Levels |
| Data Categories | High-level groupings of data types (e.g., PII, PCI, SPII). |
| Managed Data Store | A data store connected to Netskope through CASB API or DSPM (e.g., a Google Drive or AWS S3 bucket configured in your tenant). |
| Unmanaged Destination | A destination detected only through Real-Time Protection, without a configured API connection. |
| Internal User | A human identity with an email matching your organization’s internal domain. |
| External User | A human identity with an email not matching your internal domain (e.g., a vendor). |
| Unlinked | An identity that cannot be classified as internal or external. |
Getting Started
The DataSec Command Center Overview page provides high-level insights on your data security posture, including critical risks, sensitive data trends, identity coverage, and data store protection.
From the Overview, you can go to:
- Data Stores and Destinations: Explore managed data stores and unmanaged destinations across your environment.
- DCC Identities: Review identity access to sensitive data, categorized by internal, external, and unlinked users.
- Risk Policies and Remediation: Assess risk policy violations and trigger remediation workflows.
- Global Search: Search across all entities including data stores, identities, files, and data types.

