12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5Integrating <strong>McAfee</strong> DLP EndpointUnified policies and <strong>McAfee</strong> DLP EndpointAdding endpoint parameters to rules in <strong>McAfee</strong> DLP ManagerWhen added to the existing rules in the product suite, endpoint parameters can be used to extendinternationalized standard or customized rules to computers, removable media, printers, clipboards,screens, windows, shares and paths.Protection rulesProtection rules can be added from the Endpoint category on the Add or Edit Rule page. They includereactions that vary depending on a number of conditions, including whether the user is on‐ or off‐site.For example, a user who attempts to upload a file to a social media site might be prevented fromdoing so by implementing the Web Post Protection Rule, which can be configured to send notificationof the event and store evidence relating to it.Protection rules define the reactions that are to be taken when an attempt is made to transfer ortransmit tagged data. Each protection rule can deploy different combinations of actions, which can beviewed by selecting an action rule under Policies | Action Rules | <strong>Data</strong>‐in‐Use.ExceptionsIf a unified rule contains attributes that are not supported by <strong>McAfee</strong> DLP Endpoint, the rule will notproduce accurate results. Do not use the following attributes in rules that are deployed to endpoints.• Email address sender variants• Email subject (except for the condition contains none of, which is supported)• GeoIP locations• User city• User country• File size• Keyword expressions• Concept expressionsKeywords and concepts used with any of, all of, and none of conditions are used are supported (as arekeywords defined by exact phrases). Only the keyword and concept expression condition, which is usedto build complex command line queries using logical operators, is unsupported.Add endpoint protection to existing rulesYou can add protection to existing unified rules by adding Endpoint parameters.Open the Endpoint component on any Edit Rule page to see what parameters are available.For example, you might add a Protect Network Printers parameter to an existing Banking and FinancialSector rule to block endpoint computer users from printing sensitive financial data.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies and click any rule under anypolicy.• On your <strong>McAfee</strong> DLP appliance, select Policies and click on any rule under any policy.2 Open the Endpoint component.144 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!