12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5Integrating <strong>McAfee</strong> DLP EndpointUnified policies and <strong>McAfee</strong> DLP EndpointPolicy modifications are posted every 30 seconds to keep up with updated rule definitions, but you candefine a more conservative transfer interval (up to two hours, or 7200 seconds) by editing the TimeDuration for Posting Policy Definition setting.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Sys Config | Endpoint Configuration |Miscellaneous and click Manage Endpoints.• On your <strong>McAfee</strong> DLP appliance, select System | Endpoint Configuration | Miscellaneous and click ManageEndpoints.2 Select the Generate Policy for Endpoint checkbox.3 In the Time Duration for Posting Policy Definition field, enter a number between 30 and 7200 seconds.The policy is generated, posted from <strong>McAfee</strong> DLP Manager to ePolicy Orchestrator, saved in thedatabase, forwarded to the connected agents, and updated at the defined interval.4 Click Submit.Unified policies and <strong>McAfee</strong> DLP EndpointIn <strong>McAfee</strong> Host DLP, rule definitions shared a single global policy definition for all rules. In the unifiedpolicy design, the global policy is used to add <strong>McAfee</strong> DLP Endpoint functionality to the networkproduct suite.The networked products protect email and webmail through the unified rules, but there is someduplication of functionality because <strong>McAfee</strong> Host DLP (<strong>McAfee</strong> DLP Endpoint) already protected thatdata.Unified rules specifically incorporate Endpoint parameters, such as the protection rules and tagging, butthe Content category and much of the Source/Destination category contain additional parameters that canbe used on endpoints as well as networks. For example, the GeoIP location feature is supported onlyby the network products.The unified rules can also use data captured by <strong>McAfee</strong> DLP Monitor or scanned by <strong>McAfee</strong> DLPDiscover scans to adapt to changing conditions.Because all of these capabilities are integrated into the unified policy design, one rule can beconfigured to add incidents and events to all three dashboards (<strong>Data</strong>‐in‐Motion, <strong>Data</strong>‐at‐Rest, <strong>Data</strong>‐in‐Use). Forexample, a Payment Card Industry policy that has been deployed on <strong>McAfee</strong> DLP Manager can be usedto identify privacy violations in network traffic, in data repositories, and on endpoints.You can use templates to add frequently‐used actions and conditions to a rule, increasing its efficiencyand scope. If the rule is to be applied to endpoints, select Template from the Endpoint category and click ?to launch the available selection. If none are available, add a new one on the Policies | Templates | AddTemplate page using the Endpoint component type.Endpoints might be computer‐ or user‐defined, but computer assignment groups are outside of thescope of unified policy management, and can only be defined in ePolicy Orchestrator. Endpoints can bemonitored from <strong>McAfee</strong> DLP Manager by adding user‐based parameters (such as groups andorganizational units) to a rule.142 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!