tencent cloud

TDSQL-C for MySQL

DocumentationTDSQL-C for MySQLData security auditIntroduction to Data Security Audit

Introduction to Data Security Audit

Download
Focus Mode
Font Size
Last updated: 2026-08-25 15:41:06
AI-Translated
Data Security Posture Management (DSPM) and database build a unified operational view for cloud data security, allowing you to gain full visibility into the distribution and access of cloud data assets and sensitive data. Leveraging cloud-native behavior logs and a dynamic risk detection engine, the system performs end-to-end monitoring across public and private network entry points, covering asset discovery, access permission control, and risk identification. This enables visualized, controllable, and precise protection of data assets, ensures data security and compliance in the cloud, and truly delivers "visibility, control, and precision in protection."

Key Challenges in Data Security

Data assets have blind spots, and the distribution of sensitive data is unclear: Database instances are scattered across different regions, VPCs, and business departments, lacking a unified asset inventory. With a massive number of database tables and fields, the locations of sensitive data are unclear, making it difficult for security teams to accurately identify protection targets.
Data access behaviors are invisible, making traceability difficult: Every query, export, and modification operation on the database lacks a unified audit view, and high-risk behaviors such as public IP address access, operations during abnormal hours, and batch downloads cannot be detected in a timely manner. Once a data breach occurs, administrators must manually piece together logs across platforms, resulting in a lengthy traceability cycle and an incomplete evidence chain, which can easily cause them to miss the golden window for response.
Abnormal operations are difficult to identify, and risk response is delayed: Traditional rule engines generate alarms only through single-point feature matching, such as the number of failed logins, and cannot identify combined behavior risks, such as "public network access + sensitive data + batch export." As a result, a large number of alarms are generated with little useful information, causing security teams to suffer from "alarm fatigue" and struggle to prioritize responses and quickly contain the impact.
Compliance audit pressure is high, and sensitive data processing lacks a clear basis: To meet compliance requirements, enterprises need to classify and tier their data and possess full operation audit capabilities. However, manually inventorying assets, identifying sensitive data table by table and field by field, and auditing operation logs manually involve an enormous workload, resulting in high compliance costs that are difficult to sustain.

Use Cases

Core data asset protection: Perform full access auditing on sensitive data in cloud databases, such as personal information and transaction records, to provide traceability evidence for events including data breaches and unauthorized access.
Cybersecurity Classified Protection Compliance Service and regulatory compliance: Meet the requirements of laws and regulations for log retention and audit capabilities, as well as the compliance audit needs of industries such as finance and telecommunications for classified protection standards.
Database attack and risk monitoring: Monitor and generate alarms for malicious activities targeting databases in real time, enabling in-process blocking and post-incident accountability.
Ops and development security audit: Audit high-risk operations performed by Ops personnel through tools such as the console, including DROP/ALTER and batch export. Also identify risks in development and testing environments caused by sensitive data exposure or unauthorized export.

Advantages

Access relationships at a glance: Access relationships are visualized and clearly displayed.
Full operation traceability: Record every database operation to support post-incident restoration.
Real-time risk monitoring: Monitor abnormal access and sensitive operations in real time to promptly identify potential risks.
Automatic sensitive data discovery: Proactively identify the distribution of sensitive data to provide a basis for permission reduction.

Billing Overview

Data Security Audit uses a prepaid yearly/monthly subscription model and is sold in packages. You can choose an appropriate number of packages based on your actual needs. The billable items and billing standards are listed in the following table.
Note:
Each of the following packages includes: one database instance, a throughput of 1,000 SQL/second, storage for 20 million online SQL statements, and 100 GB of storage space.
Billable Item
Specifications
Unit Price
Enterprise Edition
1 - 3 sets
USD 280/set/month
4 - 20 sets
USD 270/set/month
21 - 50 sets
USD 255/set/month
51 - 100 sets
USD 240/set/month
101 - 200 sets
USD 225/set/month
201 - 300 sets
USD 210/set/month
301 - 400 sets
USD 195/set/month
401 - 500 sets
USD 180/set/month
More than 500 sets (excluding 500)
USD 150/set/month
Log Storage Expansion Pack
1TB
USD 150/month

Supported Versions

Database Type
Version
Security audit
Data Identification
TDSQL-C for MySQL
Provisioned resource
Transaction cluster - MySQL 5.7
Transaction cluster - MySQL 8.0
Read-only instances
Serverless
Serverless - MySQL 5.7
Serverless - MySQL 8.0

Supported Region

TDSQL-C for MySQL supports Data Security Audit in the following regions: Guangzhou, Shanghai, Beijing, Nanjing, Chengdu, Chongqing, Shanghai Finance, Beijing Finance, and Shenzhen Finance.

References

Related Feature
Description
Documentation Link
Purchase Data Security Audit
Describes how to purchase Data Security Audit in the console.
Enable or Disable Data Security Audit
Describes how to enable or disable Data Security Audit in the console.
Data identification
Describes operations related to the data identification capability of Data Security Audit.
Access topology
Describes the CAM capability of Data Security Audit.
Log audit
Describes the audit log capability of Data Security Audit.
Alarm
Describes the alarm capability of Data Security Audit.
Alarm
Risk
Describes the risk monitoring capability of Data Security Audit.
Risk

Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback