12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Using <strong>McAfee</strong> DLP DiscoverRemediating incidents 44 Open Email Notification to alert one or more users when the action is triggered.You can use Dynamic Variables to inform users of the prevented action automatically.For example, ##Filename found by the ##Rule violated the ##Policy and was quarantined.For example, ##Filename found by ##ScanOperation violated the ##Policy and was moved to.5 Open Syslog Notification and select Enable to log the incident (optional).6 Open Incident Reviewer to assign a reviewer when the action takes place (recommended).7 Open Incident Status to change the stage of resolution when the action takes place (recommended).8 Open Remediation Policy and select Move from the Action list.9 Select the quarantine location from the Destination drop‐down list.10 Click Save.Encrypt discovered filesEncrypt discovered files when they are found by providing passwords that must be used to accessthem. With this release, the default openssl utility used to encrypt discovered files is replaced with the<strong>McAfee</strong> ® Endpoint Encryption for Files and Folders algorithm.The encryption key is stored in ePolicy Orchestrator databases and an ePolicy Orchestrator extensionis used to display the list of keys stored.When you copy, move, delete or encrypt a file, <strong>McAfee</strong> DLP Discover leaves a trace file at the originallocation to leave a record of the remedial process that has been applied.You can use Dynamic Variables to automatically inform users that the file has been encrypted.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies | Action Rules.• On your <strong>McAfee</strong> DLP appliance, select Policies | Action Rules.2 From the Actions menu, select Add Action Rule.3 Type in a name for the action rule.4 Open Syslog Notification and select Enable to log the incident (optional).You can use Dynamic Variables to inform users of the encryption automatically.For example, ##Filename found by the ##Rule found by the ##ScanOperation was encrypted.5 Add File Marker Text to change the stage of resolution when the action takes place (recommended).6 Open Incident Reviewer to assign a reviewer when encryption occurs (recommended).7 Open Incident Status to change the stage of resolution when encryption occurs (recommended).8 Open Remediation Policy and select Encrypt from the Action list.9 Enter a password and confirm it.10 Click Save.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 119

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!