Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    DataSec Command Center

    DataSec Command Center

    DataSec Command Center (DCC) is a Netskope capability that provides unified visibility, risk assessment, and remediation for data security across your organization. As sensitive data spreads across SaaS applications, IaaS environments, and on-premises infrastructure, DCC enables security teams to:

    • Discover and monitor sensitive data across connected data stores and inline destinations.
    • Assess data security risks through predefined risk policies.
    • Remediate findings through retroactive scans, ongoing policies, or real-time protection rules.

    Supported Products

    DataSec Command Center consolidates signals from three Netskope products:

    • CASB API: Provides visibility into SaaS application data stores through API-based connections. To surface CASB API data in DCC, enable DSPM for each app instance in your tenant.
    • DSPM: Provides visibility into sensitive data and its risks across IaaS, PaaS, SaaS, and on-premises data stores through discovery and ongoing scans.
    • Real-Time Protection (Inline): Provides visibility into data in motion through inline traffic inspection.

    To learn more about connecting data stores for CASB API and DSPM: Connecting Data Stores

    DataSec Command Center works with any combination of these products. The features and data available depend on which products you license and configure.

    Key Concepts

    To successfully navigate DataSec Command Center, familiarize yourself with the following foundational terms:

    ConceptDefinition
    Stored Data (Data at Rest)Data residing in connected data stores, scanned through DSPM.
    Transfered Data (Data in Motion)Data uploaded or downloaded, detected through Real-Time Protection.
    Data TypesPredefined DLP entity classifications of sensitive data (e.g., personal name, payment card, email address). Each data type maps to one data category. To learn more: Configure Entity Data Types and Sensitivity Levels
    Data CategoriesHigh-level groupings of data types (e.g., PII, PCI, SPII).
    Managed Data StoreA data store connected to Netskope through CASB API or DSPM (e.g., a Google Drive or AWS S3 bucket configured in your tenant).
    Unmanaged DestinationA destination detected only through Real-Time Protection, without a configured API connection.
    Internal UserA human identity with an email matching your organization’s internal domain.
    External UserA human identity with an email not matching your internal domain (e.g., a vendor).
    UnlinkedAn identity that cannot be classified as internal or external.

    Getting Started

    The DataSec Command Center Overview page provides high-level insights on your data security posture, including critical risks, sensitive data trends, identity coverage, and data store protection.

    From the Overview, you can go to:

    • Data Stores and Destinations: Explore managed data stores and unmanaged destinations across your environment.
    • DCC Identities: Review identity access to sensitive data, categorized by internal, external, and unlinked users.
    • Risk Policies and Remediation: Assess risk policy violations and trigger remediation workflows.
    • Global Search: Search across all entities including data stores, identities, files, and data types.

    In this Topic
    • DataSec Command Center