[Yandex Cloud documentation](../../../index.md) > [Yandex Security Deck](../../index.md) > [Step-by-step guides](../index.md) > [Security Deck workspaces](index.md) > Updating a workspace

# Updating a Security Deck workspace and its components

## Updating a Yandex Security Deck workspace

To update a Security Deck [workspace](../../concepts/workspace.md):

{% list tabs group=instructions %}

- Security Deck UI {#cloud-sd}

  1. Go to [Yandex Security Deck](https://center.yandex.cloud/security/).
  1. In the left-hand panel, select ![sliders](../../../_assets/console-icons/sliders.svg) **Security Deck parameters** and go to the **Workspaces** tab.
  1. In the list that opens, click the required workspace to update its settings.

      {% note tip %}

      To quickly find the workspace of interest, use the filter.

      {% endnote %}

  1. Optionally, navigate to the **Main parameters** tab and update the basic workspace settings:

      1. Under **Workspace name**, update the workspace name and description.
      1. Under **Alert sink**, select the [alert sink](../../concepts/workspace.md#alert-sinks) to receive all [alerts](../../concepts/alerts.md) generated in the workspace.
         
         Create a new alert sink if needed. Do it by clicking **Create sink**. In the window that opens, enter enter a name for the sink **Create**.
      1. Click **Save** to save your changes.
  1. Optionally, click the **Resources** tab to update the list of resources controlled by the workspace:

      1. Update the resource list. You can do this with the current [connector](../../concepts/workspace.md#connectors) settings, by changing the connector settings, or by replacing the connector with a different one:

          {% list tabs %}

          - Current settings

            1. In the section with the connector name, click ![circle-plus](../../../_assets/console-icons/circle-plus.svg) **Select cloud/catalog** to update the resources ([clouds](../../../resource-manager/concepts/resources-hierarchy.md#cloud) and [folders](../../../resource-manager/concepts/resources-hierarchy.md#folder)) the workspace will control the security of. In the window that opens:

                1. Select the resources whose security you want to control in the workspace. You can only select resources that are accessible to the service account linked to the connector.
                1. Click **Save selection**.

          - Updating settings

            1. In the section with the connector name, click ![ellipsis](../../../_assets/console-icons/ellipsis.svg) and select ![pencil](../../../_assets/console-icons/pencil.svg) **Edit connector**. In the window that opens:

                1. Change the connector's name in the **Name** field.
                1. Optionally, give the connector's description in the **Description** field.
                1. Update the [service account](../../../iam/concepts/users/service-accounts.md) for access to cloud resources in the **Service account** field.
                
                    In the section below, you can see which resources the selected service account has access to.
                    
                    Make sure to assign the `security-deck.worker` [role](../../security/index.md#security-deck-worker) to this service account for the resources controlled in the workspace being created.
                
                1. Click **Save**.

             1. In the connector section that appears, click ![circle-plus](../../../_assets/console-icons/circle-plus.svg) **Select cloud/catalog** to select the resources ([clouds](../../../resource-manager/concepts/resources-hierarchy.md#cloud) and [folders](../../../resource-manager/concepts/resources-hierarchy.md#folder)) whose security will be managed in the new workspace:
                
                1. Select the resources whose security you want to manage in the workspace. You can only select the resources that are accessible to the previously selected service account.
                1. Click **Save selection**.

          - Replacing a connector

            1. In the section with the connector name, click ![ellipsis](../../../_assets/console-icons/ellipsis.svg) and select ![trash-bin](../../../_assets/console-icons/trash-bin.svg) **Delete**.
            1. Click the **Add resources** ![chevron-down](../../../_assets/console-icons/chevron-down.svg) field and select the required connector from the list that opens.

                If needed, create a new connector:
                
                1. Click ![plug-connection](../../../_assets/console-icons/plug-connection.svg) **Create connector** and in the window that opens:
                
                    1. In the **Name** field, enter a name for the connector.
                    1. Optionally, give the connector's description in the **Description** field.
                    1. Select the [service account](../../../iam/concepts/users/service-accounts.md) for access to cloud resources in the **Service account** field.
                
                        In the section below, you can see which resources the selected service account has access to.
                        
                        Make sure to assign the `security-deck.worker` [role](../../security/index.md#security-deck-worker) to this service account for the resources controlled in the workspace being created.
                
                    1. Click **Create connector**.

            1. In the connector section that appears, click ![circle-plus](../../../_assets/console-icons/circle-plus.svg) **Select cloud/catalog** to select the resources ([clouds](../../../resource-manager/concepts/resources-hierarchy.md#cloud) and [folders](../../../resource-manager/concepts/resources-hierarchy.md#folder)) whose security will be managed in the new workspace:
               
               1. Select the resources whose security you want to manage in the workspace. You can only select the resources that are accessible to the previously selected service account.
               1. Click **Save selection**.

          {% endlist %}

      1. Click **Save** to save your changes.
  1. Optionally, navigate to the **Control modules** tab to update the list of standards against which workspace-controlled resources will be checked:

      1. Under **Sets of requirements**, select the required standards:
      
          * ![base-standard-yc](../../../_assets/security-deck/cspm-base-yc.svg) [Yandex Cloud](../../concepts/standard-compliance/yc-security-baseline.md) basic security rules: Minimum set of security requirements ensuring basic protection of cloud infrastructure and applications deployed on the Yandex Cloud platform.
          * ![cspm-standard-yc](../../../_assets/security-deck/cspm-standard-yc.svg) [Yandex Cloud](../../concepts/standard-compliance/yc-cloud-security-standard.md) cloud infrastructure protection standard: [Standard](../../../security/standard/all.md) providing comprehensive security requirements and best practices for protection of the cloud infrastructure and applications deployed on the Yandex Cloud platform. These elements help ensure security policy compliance and protection against common threats and vulnerabilities in the cloud environment.
          * ![pci-dss-standard](../../../_assets/security-deck/cspm-pci-dss.svg) [PCI DSS](https://yandex.cloud/en/security/standards/pci) (Payment Card Industry Data Security Standard): Data security standard for payment cards that includes requirements for security management, rules, procedures, network architecture, software development, and other critical security measures.
          * ![152-fz-standard](../../../_assets/security-deck/cspm-152-fz.svg) [FSTEC Requirements (Order No. 21) for the protection of personal data](https://fstec.ru/dokumenty/vse-dokumenty/prikazy/prikaz-fstek-rossii-ot-18-fevralya-2013-g-n-21): Standard providing measures for protection of personal data from unauthorized or accidental access, destruction, modification, blocking, copying, disclosure, distribution, or other unlawful actions.
          
          * ![cspm-standard-k8s-restricted](../../../_assets/security-deck/cspm-standard-k8s-restricted.svg) Kubernetes Pod Security Standards (Restricted): This standard contains security controls based on the [Kubernetes Pod Security Standards (PSS) Restricted profile](https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted). A restricted profile is the most secure and provides the highest detection efficiency for container-based attacks. It applies strict security policies that may require modifying applications to ensure compliance. A restricted profile is recommended for security-critical applications and environments where maximum security is required.
          * ![cspm-standard-k8s-baseline](../../../_assets/security-deck/cspm-standard-k8s-baseline.svg) Kubernetes Pod Security Standards (Baseline): This standard contains security controls based on the [Kubernetes Pod Security Standards (PSS) Baseline profile](https://kubernetes.io/docs/concepts/security/pod-security-standards/#baseline). A baseline profile is designed for easy implementation and provides common best practices for container security. It prevents the most common security issues in containers while maintaining compatibility with most applications. The baseline profile is a good starting point for organizations just getting started with container security.
          * ![cspm-standard-k8s-ms](../../../_assets/security-deck/cspm-standard-k8s-ms.svg) Microsoft Threat Matrix for Kubernetes: This standard contains security controls based on the [Microsoft Threat Matrix for Kubernetes](https://www.microsoft.com/en-us/security/blog/2020/04/02/attack-matrix-kubernetes/), which is a framework that helps security teams understand and fend off threats specific to Kubernetes environments. It provides a comprehensive approach to attack methods and defensive strategies tailored for container orchestration platforms.
          * ![cspm-cis-k8s-standard](../../../_assets/security-deck/cspm-cis-k8s-standard.svg) CIS Kubernetes Benchmark: This standard contains [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes) recommendations for secure configuration of components on Kubernetes worker nodes. It includes only the automated checks from the `4 Worker Nodes` section.
      
          You can select several standards at the same time. The **Control modules** section will thus get new Security Deck modules, which will be activated in the new workspace to check your resources for compliance with the selected standards and regulations.
      1. Optionally, under **Control modules**, activate additional Security Deck modules that you need in your environment.
         
         For example, the **Data Security Posture Management (DSPM)
         ** module is independent of the standards and regulations selected in the environment and must be activated manually for the environment in question.
      1. Click **Save** to save your changes.
  1. Optionally, navigate to the **Kubernetes® Security Posture Management** tab to update the security control settings for Kubernetes clusters.

{% endlist %}

{% note info %}

You cannot update the folder that the workspace uses to store its resources and settings.

{% endnote %}

## Editing a connector {#update-connector}

To update a Security Deck [connector](../../concepts/workspace.md#connectors):

{% list tabs group=instructions %}

- Security Deck UI {#cloud-sd}

  1. Go to [Yandex Security Deck](https://center.yandex.cloud/security/).
  1. In the left-hand panel, select ![sliders](../../../_assets/console-icons/sliders.svg) **Security Deck parameters** and go to the **Connectors** tab.

      {% note tip %}

      To quickly find the connector you need, use the filter.

      {% endnote %}

  1. In the list that opens, click ![ellipsis](../../../_assets/console-icons/ellipsis.svg) in the row with the required connector and select ![pencil](../../../_assets/console-icons/pencil.svg) **Edit**. In the window that opens:

      1. Change the connector's name in the **Name** field.
      1. Optionally, give the connector's description in the **Description** field.
      1. Update the [service account](../../../iam/concepts/users/service-accounts.md) for access to cloud resources in the **Service account** field.
      
          In the section below, you can see which resources the selected service account has access to.
          
          Make sure to assign the `security-deck.worker` [role](../../security/index.md#security-deck-worker) to this service account for the resources controlled in the workspace being created.
      
      1. Click **Save**.

{% endlist %}

## Updating an alert sink {#update-alert-sink}

To update a Security Deck [alert sink](../../concepts/workspace.md#alert-sinks):

{% list tabs group=instructions %}

- Security Deck UI {#cloud-sd}

  1. Go to [Yandex Security Deck](https://center.yandex.cloud/security/).
  1. In the left-hand panel, select ![sliders](../../../_assets/console-icons/sliders.svg) **Security Deck parameters** and go to the **Alert Sinks** tab.

      {% note tip %}

      To quickly find the alert sink you need, use the filter.

      {% endnote %}
  1. In the list that opens, click ![ellipsis](../../../_assets/console-icons/ellipsis.svg) in the row with the required connector and select ![pencil](../../../_assets/console-icons/pencil.svg) **Edit**.
  1. In the window that opens, update the alert sink settings and click **Save**.

{% endlist %}

#### Useful links {#see-also}

* [Security Deck workspaces](../../concepts/workspace.md)
* [Creating a Security Deck workspace](create.md)
* [Viewing the workspace dashboard and operations in Security Deck](view-dashboard.md)
* [Configuring the Security Deck workspace access permissions](manage-access.md)
* [Deleting a Security Deck workspace](delete.md)