McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide McAfee Data Loss Prevention 9.2.2 Product Guide

kb.mcafee.com
from kb.mcafee.com More from this publisher
12.07.2015 Views

8Working with casesManage case permissionsTask1 Select one of these options:• In ePolicy Orchestrator, select Menu | Data Loss Prevention | DLP Reporting | Incidents.• On your McAfee DLP appliance, select Incidents.2 Find credit card violations on the dashboard, then select one or more incident checkboxes.3 Click Assign to Case, then select New Case or Existing Case from the sub‐menu.• If you select New Case, complete the Case Details page, and click Apply.• If you select Existing Case, choose a case on the list, click its Assign link, complete the Case Detailspage, and click Apply.If you cannot see the Assign column, expand your dashboard.4 From the Options menu, select Customize Case Config and add attributes that might help you to put eachincident into a customized context.For example, you might add a source field that allows you to type a note on the Case Details pageabout the origin of the incident.5 From the Options menu, select Customize Columns and rearrange the dashboard to display only the mostuseful attributes of the object found.6 From the Options menu, select Customize Case Config and select Owner and Submitter checkboxes to keepthe stakeholders updated on the progress of the case.7 On the Case List, open the credit card violation case and examine each of the incidents in the case tofind out what they have in common.8 Update the Notes field on the Case Details page each time a new violation is added to the case, orwhenever you or your collaborators find another piece of the puzzle.By cooperating in developing the case, you and your colleagues can act as a team to find out howcredit card violations are generated, devise a process to prevent more of them, and if the data lossis not accidental, build a legal case against the perpetrators.Manage case permissionsThere are two levels of case permissions: administrators can assign case permissions to groups ofusers whose roles require case access; and users who have been given case permissions can manageaccess to specific cases.Administrators have permissions to assign, manage, export, and delete case permissions to usergroups, and they can also override permissions assigned to individual users. Case users can assignread, write, and delete permissions for a case to other groups or individual users.Access to the case permissions page requires at least case‐level read and delete permissions, plustask‐level management permission assigned by an administrator. If write permission is assigned on thecase management page, read access is included, even if that permission is not explicitly assigned.190 McAfee Data Loss Prevention 9.2.2 Product Guide

Working with casesManage case permissions 8The multi‐level case permissions system makes it possible to restrict case access to users who aretasked with a particular case or type of case. For example, permissions can be set so that members ofan Operations group cannot view confidential personnel cases that are managed by members of aHuman Resources group.If the user is not authorized to complete this task, the Permission menu item is disabled.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | Data Loss Prevention | DLP Reporting | Case Management.• On your McAfee DLP appliance, select Case | Case Management.2 Select a case and click Details.3 Select Options | Permissions.4 Select the Read, Write, or Delete checkboxes corresponding to the assignment of the case to users andgroups.Users who create cases are automatically allocated all three permissions — but if a case owner ischanged, permissions are lost.5 Click Apply.Global permissions take precedence over cases configured individually. If there is a conflict betweenpermissions assigned under an individual case and those that are assigned globally, global grouppermissions take precedence.• In ePolicy Orchestrator, global permissions are set under Menu | Data Loss Prevention | DLPSys Config | User Administration | Groups | Details | Task Permissions.• On your McAfee DLP appliance, global permissions are set under System | UserAdministration | Groups | Details | Task Permissions.When Write permission is assigned, Read permission is implicit.How user permissions might be assignedJohn has been given read access, so case information is displayed on his home page. Butbecause his permission is restricted to Read, he will not see the Apply, Save, Delete, or Assignbuttons.Sheila has been given responsibility for developing court cases, so she has been given Readand Write but not Delete permissions. Because of the nature of legal actions, only her managercan see the Delete button on his console.McAfee Data Loss Prevention 9.2.2 Product Guide 191

Working with casesManage case permissions 8The multi‐level case permissions system makes it possible to restrict case access to users who aretasked with a particular case or type of case. For example, permissions can be set so that members ofan Operations group cannot view confidential personnel cases that are managed by members of aHuman Resources group.If the user is not authorized to complete this task, the Permission menu item is disabled.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Reporting | Case Management.• On your <strong>McAfee</strong> DLP appliance, select Case | Case Management.2 Select a case and click Details.3 Select Options | Permissions.4 Select the Read, Write, or Delete checkboxes corresponding to the assignment of the case to users andgroups.Users who create cases are automatically allocated all three permissions — but if a case owner ischanged, permissions are lost.5 Click Apply.Global permissions take precedence over cases configured individually. If there is a conflict betweenpermissions assigned under an individual case and those that are assigned globally, global grouppermissions take precedence.• In ePolicy Orchestrator, global permissions are set under Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLPSys Config | User Administration | Groups | Details | Task Permissions.• On your <strong>McAfee</strong> DLP appliance, global permissions are set under System | UserAdministration | Groups | Details | Task Permissions.When Write permission is assigned, Read permission is implicit.How user permissions might be assignedJohn has been given read access, so case information is displayed on his home page. Butbecause his permission is restricted to Read, he will not see the Apply, Save, Delete, or Assignbuttons.Sheila has been given responsibility for developing court cases, so she has been given Readand Write but not Delete permissions. Because of the nature of legal actions, only her managercan see the Delete button on his console.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 191

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!