Download Network Data Loss Prevention 9.3.0 Product Guide - Rev E
Transcript
12 Policy configuration options Rule options Rule options Rules contain conditions configured on three tabs. • The Define tab contains parameters to match inspected data. • The Actions tab specifies the action to take on matching data. • The Exceptions tab specifies exceptions for the rule. Up to eight exceptions can be specified using all of the parameters available on the Define tab, except for Endpoint and Date/Time. Table 12-2 Rule parameter options Option Definition Applicable products Content Defines patterns of data with keywords, concepts, content types, or templates. Any Source/Destination Specifies a source or destination IP address, email address, URL or Active Directory information. • McAfee DLP Monitor • McAfee DLP Prevent File Information Defines files according to size, signature, document properties definitions, or template. Any Protocol Specifies a network protocol or port. • McAfee DLP Monitor • McAfee DLP Prevent Discover Defines the scan using parameters such as scan operation, host IP address, repository type, domain name, and so forth. McAfee DLP Discover Endpoint Defines conditions specific to McAfee DLP Endpoint. McAfee DLP Endpoint This option is not available on the Exceptions tab. Date/Time Defines the file by creation time, last modification time, or last access time. Any This option is not available on the Exceptions tab. Action rule options Action rules apply preventive or corrective actions when rules generate incidents. The actions available depend on which McAfee DLP product implements them. When creating a new McAfee DLP action rule, the default action is None. This allows you to monitor the system and collect data before deciding which action is appropriate. You can enable notification with any action. McAfee DLP Prevent must have an action rule configured for the rule to be active. Table 12-3 Action rule options McAfee DLP product Available actions McAfee DLP Monitor Allow McAfee DLP Prevent with a proxy server • Block • Monitor 140 McAfee Data Loss Prevention 9.3.0 Product Guide