Download Network Data Loss Prevention 9.3.0 Product Guide - Rev E

Transcript
12
Policy configuration options
Rule options
Rule options
Rules contain conditions configured on three tabs.
•
The Define tab contains parameters to match inspected data.
•
The Actions tab specifies the action to take on matching data.
•
The Exceptions tab specifies exceptions for the rule. Up to eight exceptions can be specified using all
of the parameters available on the Define tab, except for Endpoint and Date/Time.
Table 12-2 Rule parameter options
Option
Definition
Applicable products
Content
Defines patterns of data with keywords, concepts, content
types, or templates.
Any
Source/Destination Specifies a source or destination IP address, email address,
URL or Active Directory information.
• McAfee DLP Monitor
• McAfee DLP Prevent
File Information
Defines files according to size, signature, document
properties definitions, or template.
Any
Protocol
Specifies a network protocol or port.
• McAfee DLP Monitor
• McAfee DLP Prevent
Discover
Defines the scan using parameters such as scan operation,
host IP address, repository type, domain name, and so forth.
McAfee DLP Discover
Endpoint
Defines conditions specific to McAfee DLP Endpoint.
McAfee DLP Endpoint
This option is not available on the Exceptions tab.
Date/Time
Defines the file by creation time, last modification time, or
last access time.
Any
This option is not available on the Exceptions tab.
Action rule options
Action rules apply preventive or corrective actions when rules generate incidents. The actions available
depend on which McAfee DLP product implements them.
When creating a new McAfee DLP action rule, the default action is None. This allows you to monitor the
system and collect data before deciding which action is appropriate. You can enable notification with
any action.
McAfee DLP Prevent must have an action rule configured for the rule to be active.
Table 12-3 Action rule options
McAfee DLP product
Available actions
McAfee DLP Monitor
Allow
McAfee DLP Prevent with a proxy server
• Block
• Monitor
140
McAfee Data Loss Prevention 9.3.0
Product Guide