12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Integrating <strong>McAfee</strong> DLP EndpointUnified policies and <strong>McAfee</strong> DLP Endpoint 53 Select an endpoint parameter and define it. If it is a protection rule, click ?, then select Enable andApply.Protection rules are disabled by default.4 If a reaction is to be added, click the Actions tab, then Add Action.5 Select a suitable action from the <strong>Data</strong> in Use section.6 Click Save.Assign events to casesIf further investigation is warranted, you can assign events to the same cases as <strong>Data</strong>‐at‐Rest and<strong>Data</strong>‐in‐Motion incidents.If an error is encountered while assigning incidents to a case (for example, the object cannot be fetchedfrom the evidence share), you must reassign each of the failed incidents to the case.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Reporting | Incidents.• On your <strong>McAfee</strong> DLP appliance, select Incidents.2 From the <strong>Data</strong>‐in‐Use dashboard, select one or more endpoint events.3 Click Assign to Case and select New Case or Existing Case from the sub‐menu.4 Click Apply.Using protection rules in <strong>McAfee</strong> DLP ManagerYou can deploy discovery, application, and web post protection rules to endpoints by adding them tounified rules. You can deploy the reactions associated with them by adding action rules.The reactions applied by protection rules have become <strong>Data</strong>‐in‐Use action rules in <strong>McAfee</strong> DLP Manager,and they are disabled by default. Before a protection rule can be added to a unified rule, it must beselected from the Endpoint category on the Edit Rule page and Enabled on the pop‐up menu.Protection rule reactions are defined on the Action Rules page under <strong>Data</strong>‐in‐Use. The following actions areavailable:• Block • Quarantine• Delete • Request Justification• Encrypt • Store Evidence• Monitor • Tag• Notify UserThere are limitations on reactions that can be used in the same action rule. For example, Block andEncrypt actions cannot be used in the same rule. You can find a complete list by clicking Tips on thePolicies | Action Rules | Add Action Rule page, which launches the Endpoint Action Rule Constraints pop‐up.When combined with <strong>Data</strong>‐in‐Motion and <strong>Data</strong>‐at‐Rest action rules, one unified rule can act on dataanywhere — on‐ or off‐site (online and offline).<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 145

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!