12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Integrating <strong>McAfee</strong> DLP EndpointControlling devices 5Add a removable storage file access ruleFile access rules control the usage of removable storage devices on the network. They can be used toblock or encrypt removable storage devices, prevent applications from being started, or restrict theactions of users.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Sys Config | Endpoint Configuration..• On your <strong>McAfee</strong> DLP appliance, select System | Endpoint Configuration.2 In the navigation pane under Device Management, select Device Rules and scroll down to the RemovableStorage File Access Rule section.The available device management rules appear in the right pane.3 From the Actions menu, select Add New.The Add Removable Storage File Access Rule window appears.4 Type in a name and optional description.5 From the State menu, select Active to activate the rule.6 If Device Definitions are to be added to the rule, select Include or Exclude checkboxes to indicate if thedevices are to be blocked or encrypted.7 If there are applications listed under the Whitelisted Applications section, select checkboxes to indicatewhich ones are to be included or excluded from the rule.8 Set a User Assignment condition if an alert is to be sent to users when the device is used on‐ or offsite.Users can be identified positively or negatively by name or affiliation, and they can be retrievedfrom an LDAP server.Click + to add multiple user assignments.9 Click Save.Add a Plug and Play device rulePlug and Play device rules can be used to block, monitor, and assign read‐only and user permissions toPlug and Play devices. Although USB devices are Plug and Play as well as removable storage devices,the latter should be used to block their use.Using a Plug and Play rule to block a USB storage device can result in blocking the entire USB Hub/Controller. Plug and Play rules are not very flexible — if a device is blocked, it is completelyunavailable for use. It is an "all or nothing" rule; if a device is allowed, it will be completely usable.You cannot block a particular feature of the device or keep the device from performing a particularaction.<strong>McAfee</strong> recommends using removable storage device rules because they allow the device to initializeand register with Windows, and the USB device can be set to read only.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Sys Config | Endpoint Configuration.• On your <strong>McAfee</strong> DLP appliance, select System | Endpoint Configuration.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 167

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!