McAfee Data Loss Prevention 9.2.2 Product Guide
McAfee Data Loss Prevention 9.2.2 Product Guide McAfee Data Loss Prevention 9.2.2 Product Guide
8Working with casesManage case permissionsTask1 Select one of these options:• In ePolicy Orchestrator, select Menu | Data Loss Prevention | DLP Reporting | Incidents.• On your McAfee DLP appliance, select Incidents.2 Find credit card violations on the dashboard, then select one or more incident checkboxes.3 Click Assign to Case, then select New Case or Existing Case from the sub‐menu.• If you select New Case, complete the Case Details page, and click Apply.• If you select Existing Case, choose a case on the list, click its Assign link, complete the Case Detailspage, and click Apply.If you cannot see the Assign column, expand your dashboard.4 From the Options menu, select Customize Case Config and add attributes that might help you to put eachincident into a customized context.For example, you might add a source field that allows you to type a note on the Case Details pageabout the origin of the incident.5 From the Options menu, select Customize Columns and rearrange the dashboard to display only the mostuseful attributes of the object found.6 From the Options menu, select Customize Case Config and select Owner and Submitter checkboxes to keepthe stakeholders updated on the progress of the case.7 On the Case List, open the credit card violation case and examine each of the incidents in the case tofind out what they have in common.8 Update the Notes field on the Case Details page each time a new violation is added to the case, orwhenever you or your collaborators find another piece of the puzzle.By cooperating in developing the case, you and your colleagues can act as a team to find out howcredit card violations are generated, devise a process to prevent more of them, and if the data lossis not accidental, build a legal case against the perpetrators.Manage case permissionsThere are two levels of case permissions: administrators can assign case permissions to groups ofusers whose roles require case access; and users who have been given case permissions can manageaccess to specific cases.Administrators have permissions to assign, manage, export, and delete case permissions to usergroups, and they can also override permissions assigned to individual users. Case users can assignread, write, and delete permissions for a case to other groups or individual users.Access to the case permissions page requires at least case‐level read and delete permissions, plustask‐level management permission assigned by an administrator. If write permission is assigned on thecase management page, read access is included, even if that permission is not explicitly assigned.190 McAfee Data Loss Prevention 9.2.2 Product Guide
Working with casesManage case permissions 8The multi‐level case permissions system makes it possible to restrict case access to users who aretasked with a particular case or type of case. For example, permissions can be set so that members ofan Operations group cannot view confidential personnel cases that are managed by members of aHuman Resources group.If the user is not authorized to complete this task, the Permission menu item is disabled.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | Data Loss Prevention | DLP Reporting | Case Management.• On your McAfee DLP appliance, select Case | Case Management.2 Select a case and click Details.3 Select Options | Permissions.4 Select the Read, Write, or Delete checkboxes corresponding to the assignment of the case to users andgroups.Users who create cases are automatically allocated all three permissions — but if a case owner ischanged, permissions are lost.5 Click Apply.Global permissions take precedence over cases configured individually. If there is a conflict betweenpermissions assigned under an individual case and those that are assigned globally, global grouppermissions take precedence.• In ePolicy Orchestrator, global permissions are set under Menu | Data Loss Prevention | DLPSys Config | User Administration | Groups | Details | Task Permissions.• On your McAfee DLP appliance, global permissions are set under System | UserAdministration | Groups | Details | Task Permissions.When Write permission is assigned, Read permission is implicit.How user permissions might be assignedJohn has been given read access, so case information is displayed on his home page. Butbecause his permission is restricted to Read, he will not see the Apply, Save, Delete, or Assignbuttons.Sheila has been given responsibility for developing court cases, so she has been given Readand Write but not Delete permissions. Because of the nature of legal actions, only her managercan see the Delete button on his console.McAfee Data Loss Prevention 9.2.2 Product Guide 191
- Page 140 and 141: 5Integrating McAfee DLP EndpointCon
- Page 142 and 143: 5Integrating McAfee DLP EndpointUni
- Page 144 and 145: 5Integrating McAfee DLP EndpointUni
- Page 146 and 147: 5Integrating McAfee DLP EndpointUni
- Page 148 and 149: 5Integrating McAfee DLP EndpointTag
- Page 150 and 151: 5Integrating McAfee DLP EndpointTag
- Page 152 and 153: 5Integrating McAfee DLP EndpointTag
- Page 154 and 155: 5Integrating McAfee DLP EndpointTag
- Page 156 and 157: 5Integrating McAfee DLP EndpointTag
- Page 158 and 159: 5Integrating McAfee DLP EndpointTag
- Page 160 and 161: 5Integrating McAfee DLP EndpointCon
- Page 162 and 163: 5Integrating McAfee DLP EndpointCon
- Page 164 and 165: 5Integrating McAfee DLP EndpointCon
- Page 166 and 167: 5Integrating McAfee DLP EndpointCon
- Page 168 and 169: 5Integrating McAfee DLP EndpointCon
- Page 170 and 171: 5Integrating McAfee DLP EndpointCon
- Page 172 and 173: 6Managing the Home pageHow the Home
- Page 174 and 175: 7Using the Incidents dashboardTypic
- Page 176 and 177: 7Using the Incidents dashboardSort
- Page 178 and 179: 7Using the Incidents dashboardGetti
- Page 180 and 181: 7Using the Incidents dashboardGetti
- Page 182 and 183: 7Using the Incidents dashboardSet u
- Page 184 and 185: 7Using the Incidents dashboardGener
- Page 186 and 187: 7Using the Incidents dashboardCusto
- Page 188 and 189: 7Using the Incidents dashboardContr
- Page 192 and 193: 8Working with casesAdd, delete, or
- Page 194 and 195: 8Working with casesModify casesYou
- Page 196 and 197: 8Working with casesCustomize cases3
- Page 198 and 199: 8Working with casesCustomize cases4
- Page 200 and 201: 9Managing policies and rulesHow pol
- Page 202 and 203: 9Managing policies and rulesTypical
- Page 204 and 205: 9Managing policies and rulesTypical
- Page 206 and 207: 9Managing policies and rulesManagin
- Page 208 and 209: 9Managing policies and rulesAdd, mo
- Page 210 and 211: 9Managing policies and rulesAdd, mo
- Page 212 and 213: 9Managing policies and rulesManage
- Page 214 and 215: 9Managing policies and rulesManage
- Page 216 and 217: 9Managing policies and rulesManage
- Page 218 and 219: 9Managing policies and rulesIdentif
- Page 220 and 221: 9Managing policies and rulesIdentif
- Page 222 and 223: 10Managing action rulesHow McAfee D
- Page 224 and 225: 10Managing action rulesAdd, modify,
- Page 226 and 227: 10Managing action rulesAdd, modify,
- Page 228 and 229: 10Managing action rulesAdd, modify,
- Page 230 and 231: 10Managing action rulesAdd, modify,
- Page 232 and 233: 11Managing conceptsTypical scenario
- Page 234 and 235: 11Managing conceptsAdd, apply, rest
- Page 236 and 237: 11Managing conceptsAdd, apply, rest
- Page 238 and 239: 11Managing conceptsAdd, apply, rest
Working with casesManage case permissions 8The multi‐level case permissions system makes it possible to restrict case access to users who aretasked with a particular case or type of case. For example, permissions can be set so that members ofan Operations group cannot view confidential personnel cases that are managed by members of aHuman Resources group.If the user is not authorized to complete this task, the Permission menu item is disabled.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Reporting | Case Management.• On your <strong>McAfee</strong> DLP appliance, select Case | Case Management.2 Select a case and click Details.3 Select Options | Permissions.4 Select the Read, Write, or Delete checkboxes corresponding to the assignment of the case to users andgroups.Users who create cases are automatically allocated all three permissions — but if a case owner ischanged, permissions are lost.5 Click Apply.Global permissions take precedence over cases configured individually. If there is a conflict betweenpermissions assigned under an individual case and those that are assigned globally, global grouppermissions take precedence.• In ePolicy Orchestrator, global permissions are set under Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLPSys Config | User Administration | Groups | Details | Task Permissions.• On your <strong>McAfee</strong> DLP appliance, global permissions are set under System | UserAdministration | Groups | Details | Task Permissions.When Write permission is assigned, Read permission is implicit.How user permissions might be assignedJohn has been given read access, so case information is displayed on his home page. Butbecause his permission is restricted to Read, he will not see the Apply, Save, Delete, or Assignbuttons.Sheila has been given responsibility for developing court cases, so she has been given Readand Write but not Delete permissions. Because of the nature of legal actions, only her managercan see the Delete button on his console.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 191