12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5Integrating <strong>McAfee</strong> DLP EndpointControlling devicesAdd a removable storage device ruleRemovable storage device rules can be used to block, monitor, and assign read‐only and userpermissions to external storage devices. Although USB storage devices are Plug and Play as well asremovable storage devices, these rules should be used to block their use.Using a Plug and Play device rule to block a USB storage device can result in blocking the entire USBHub/Controller. <strong>McAfee</strong> recommends using removable storage device rules because they allow thedevice to initialize and register with Windows, and the USB device can also be set to read only.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Sys Config | Endpoint Configuration.• On your <strong>McAfee</strong> DLP appliance, select System | Endpoint Configuration.2 In the navigation pane under Device Management, select Device Rules.The available rules appear in the right pane.3 In the Removable Storage Device Rule section, select Add New from the Actions menu.The Add Removable Storage Device Rule window appears.4 Type in a name and optional description.5 From the State menu, select Active to activate the rule.6 If Device Definitions are to be added to the rule, select Include or Exclude checkboxes to indicate if thedevices are to be blocked or encrypted.7 From the Actions menu, select the checkboxes of actions that are to be executed when the rule hits.Each action can be set to execute if the user is on or off the premises, or both.• Select the Block checkbox if the device is to be blocked when the user is on‐ or offsite, or both.• Select the Monitor checkbox if the device is to be monitored when the user is on‐ or offsite, orboth. If either is selected, select a checkbox that indicates the Severity of the violation.• Select the Notify User checkbox if an alert is to be sent when users who are on‐ or offsite, or both,trigger the Block or Monitor actions.• Select the Read only checkbox if write access to the device is to be blocked when the user is onoroffsite, or both. This prevents copying to or from the device.8 Set a User Assignment condition if an alert is to be sent to users when the device is used on‐ or offsite.Users can be identified positively or negatively by name or affiliation, and they can be retrievedfrom an LDAP server.Click + to add multiple user assignments.9 Click Save.166 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!