12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing policies and rulesTypical scenarios 92 Select a policy that contains rules that need to be tuned.3 On the Edit Policy page, select the <strong>Data</strong>‐at‐Rest or <strong>Data</strong>‐in‐Motion checkboxes in the Suppress Incidentssection.4 Click Chart to find the time frame in which the policy's rules are reporting matches.5 Click Compare to find out which rule is reporting the most matches.6 After analyzing the rules, apply the parameters of each one against captured data and observe theresults.7 Repeat the process until each parameter is producing useful matches, then modify and re‐saveeach rule.8 On the Edit Policy page, click Chart and Compare to verify the efficacy of the modified policy and rules.9 If the results are acceptable, deselect the <strong>Data</strong>‐at‐Rest or <strong>Data</strong>‐in‐Motion checkboxes in the SuppressIncidents section.10 Click Save.Typical scenariosStandard policies can be used for many common use cases, and they can be easily adapted to fitcustom needs.Protect intellectual property by customizing a standard policyIf you are trying to trace the origin of an intellectual property violation, you might find the source bycustomizing the rules of the Competitive Edge policy.Before you beginOn the Policy page, check the status of the Competitive Edge policy. It should be set toActive, and all of the rules within it should be Enabled.Depending on what you know about the incident, you can refine the rules in the policy so you cangradually find the source of the problem. Adapt the following suggested parameters to your ownsystems.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies.• On your <strong>McAfee</strong> DLP appliance, select Policies.2 In the Competitive Edge policy, open the first rule.The Edit Rule page appears.3 Modify the following suggested parameters to adapt the rule to your protection strategy.• In the Content category, select Keywords contains any of, then type keywords that might be in yourconfidential documents.• Remove the Common Content Types template to limit matches to a single content type. In the Contentcategory, select Content Type contains any of, click ?, and select a file format from the pop‐up menu.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 201

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!