12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

5Integrating <strong>McAfee</strong> DLP EndpointUnified policies and <strong>McAfee</strong> DLP EndpointAdd a reactionAdd a reaction by adding a <strong>Data</strong>‐in‐Use action rule.If multiple actions are selected, they will be applied simultaneously when an event is detected. Forexample, a Removable Media reaction might block, monitor, and store evidence of a significant event,whether the device is on‐ or off‐site.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies | Action Rules.• On your <strong>McAfee</strong> DLP appliance, select Policies | Action Rules.2 From the Actions menu under <strong>Data</strong>‐in‐Use, select Add Action Rule.Endpoint actions can be taken if the detected device is on‐ or off‐site (online or offline). Select oneor both.3 Enter a name for the action rule.4 Select one or more actions to be taken.If the event detected is to be encrypted, provide an encryption key. Consult the updated EndpointEncryption for Files and Folders 4.0 <strong>Product</strong> <strong>Guide</strong> for more information.If the event detected is significant, select a Severity from the drop‐down list.If users are to be notified when the event is detected, enter a message. Entering link text or a URLis optional.5 Click Save.After you have created the endpoint action rule, apply it to one or more rules.Apply a reactionApply a reaction by selecting a <strong>Data</strong>‐in‐Use action rule and adding it to a rule.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies and click on a rule that hasone or more endpoint parameters.• On your <strong>McAfee</strong> DLP appliance, select Policies and click on a rule that has one or more endpointparameters.2 Click the Actions tab and select Add Action.3 Select one or more <strong>Data</strong>‐in‐Use actions to be taken when a protected endpoint is detected.4 Click Save.Extending <strong>McAfee</strong> DLP Discover scans to endpointsRegistered index packages found by <strong>McAfee</strong> DLP Discover are shared with other <strong>McAfee</strong> DLPappliances, and also with the <strong>McAfee</strong> DLP client, which distributes them to endpoints and controls filescontaining registered content.<strong>McAfee</strong> DLP Endpoint uses document registration and location‐based tagging to identify sensitive dataat rest on endpoints. Confidential files that were created after a tag was applied to a group of filesmight not be detected by a rule, so they could be accessed by an endpoint user. But if the location isscanned, those files at risk will be protected because they are in a defined location path.146 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!