12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5Integrating <strong>McAfee</strong> DLP EndpointTypical scenariosProtect data from screen captureIf you want to keep users to record sensitive data by capturing images on a computer, you canconfigure <strong>McAfee</strong> DLP Endpoint to disable screen capture functionality.Trusted processes are not part of the screen capture rule logic. Applications with a Trusted strategy arenot exempt from screen capture rules, and will be blocked like any other application.For example, if you want to ensure that engineering drawings cannot be captured, use an EngineeringDrawing and Design Files template with the Protect Screen Capture reaction to protect thoseproprietary documents.This procedure describes protection of engineering drawings with a template, but you could get a similarresult by adding a screen capture protection rule to the Registered Engineering Drawings and DesignFile Violations rule in the High Technology Industry IP policy.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies.• On your <strong>McAfee</strong> DLP appliance, select Policies.2 Add a policy and rule to carry and deploy the Engineering Drawing and Design Files template.Make sure the policy is active and the Inherit Policy State state of the rule is set to Enabled.3 On the Add Rule page, open the Content category.4 From the Template menu, select the Engineering Drawing and Design Files document set.5 From the Endpoint category, select Protect Screen Capture.The Enable pop‐up menu appears.6 Select the Enable checkbox and click Apply.7 Click the Actions tab and click Add Action, then select the Print Screen Reaction from the <strong>Data</strong>‐in‐Use menu.If you want to add other reactions, such as notifying the owner of the documents or storingevidence of the attempt to capture content, go to the Action Rules page, open the Print Screen Reactionaction rule, and modify it to include those actions.8 Click Save.When engineering design documents are detected on a computer, the user will not be able tocapture the image.Protect data by identifying text in title barsIf you want to keep users at endpoints from taking screenshots of specific windows, you can apply aProtect Screen Capture parameter to a unified rule.When text in title bars is used with a Protect Screen Capture reaction, the rule is refined by preventingsnapshots of windows only if they contain that title.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies.• On your <strong>McAfee</strong> DLP appliance, select Policies.134 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!