12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2Using <strong>McAfee</strong> DLP MonitorTypical scenariosTask1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Reporting | Basic Search.• On your <strong>McAfee</strong> DLP appliance, select Capture | Basic Search.2 Select Input Type | Keywords, then type a word or phrase that might be found in a sensitive document,such as Confidential.If you have additional information (such as content type or protocol), use an Advanced Search so youcan add elements to include those values.3 Select a time frame from the Date/Time menu.4 Click Search.Monitor sensitive files after close of business in different timezonesIf you are managing several <strong>McAfee</strong> DLP Monitor appliances in different time zones, you might want tomonitor data at the same local clock time in every location. For example, certain files might be allowedto enter or leave local networks during business hours — but after 5 p.m. in any time zone, it mightindicate a leak.The date and time set on your DLP appliances is determined by the local time zone in which they wereinstalled. Because local time is automatically converted to Greenwich Mean Time (GMT), you must usethe Exact Time parameter and set a local time condition.By creating a rule that tracks sensitive data between the hours of 5 and 6 p.m. in your Los Angeles,New York, London, and Tokyo offices, you can monitor data at the time most employees are leavingeach of those facilities.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Reporting | Advanced Search.• On your <strong>McAfee</strong> DLP appliance, select Capture | Advanced Search.2 Open the Date/Time category and select Exact Time.3 From the conditions menu, select before, between, or after (local time).Select between (local time) to set both before and after delimiters.4 From the calendar icon, select a date, and set hour, minute and second times with the thumbwheelmenus.5 Click Search or Save as Rule.Find email using non-standard portsWhen non‐standard ports are used to transmit email, a deliberate attempt to conceal illegal activityshould be suspected.This case helps you to eliminate email that uses well‐known ports, so that unknown or unsecuredtransmissions can be revealed.20 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!