12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5Integrating <strong>McAfee</strong> DLP EndpointControlling devices2 In the navigation pane under Device Management, select Device Rules.The available device management rules appear in the right pane.3 In the Plug and Play Device Rule section, select Add New from the Actions menu.The Add Plug and Play Device Rule window appears.You can use the Plug and Play device blocking rule to block USB devices, but <strong>McAfee</strong> recommendsusing the removable storage device blocking rule instead. Using the Plug and Play device blockingrule can result in blocking the entire USB hub/controller. The removable storage device blocking ruleallows the device to initialize and register with the operating system. It also allows you to define thedevice as read‐only.4 Type in a name and optional description.5 From the State menu, select Active to activate the rule.6 From the Device Definitions menu, select device and device group definitions to be added to orexcluded from the rule. The Exclude option is used to whitelist devices that should not be controlled.7 From the Actions menu, select the checkboxes of actions that are to be executed when the rule hits.Each action can be set to execute if the user is on or off the premises, or both.Select the Block checkbox if the device is to be blocked when the user is on‐ or offsite, or both.Select the Monitor checkbox if the device is to be monitored when the user is on‐ or offsite, or both.If either is selected, select a checkbox that indicates the Severity of the violation.Select the Notify User checkbox if an alert is to be sent when users who are on‐ or offsite, or both,trigger the Block or Monitor actions.8 Set a User Assignment condition if an alert is to be sent to users when the device is used on‐ or offsite.Users can be identified positively or negatively by name or affiliation, and they can be retrievedfrom an LDAP server.Click + to add multiple user assignments.9 Click Save.Device parametersDevice parameters are used to build device definitions, which are incorporated into device rules thatsecure sensitive data at endpoints.The following table provides definitions for all parameters used in device definitions.Device parameters cannot be imported in the <strong>McAfee</strong> DLP Manager implementation of <strong>McAfee</strong> DLPEndpoint.Table 5-2 Device definitions for plug and Play and removable storage devicesParameternameFoundin...DescriptionBus Type Both Selects the device BUS type from the available list (IDE, PCI, and soforth.)CD/DVD Drives RS only A generic category for any CD or DVD drive.168 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!