12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

9Managing policies and rulesTypical scenarios• In the Source/Destination category, select Email Address | sender is any of, then type the email addressesyou are targeting into the value field (separated by commas).• In the Source/Destination category, select UserName | sender is any of, click ?, and select the directoryserver that contains the user's account. Click Find, select the user, then click Apply. If you selectEveryone, the rule will apply to all users on your directory servers.• In the Protocol category, click ? and select FTP from the File Sharing Protocols pop‐up menu, thenclick Apply.• In the Endpoint category, select Protect Local Printers, Protect Screen Capture, select the Enable checkbox,and Apply.• In the Date/Time category, select File Last Accessed, then define the last time a confidential documentwas accessed.4 Click Actions, Add Action, and select the Print Screen Reaction or Printer Reaction from the <strong>Data</strong>‐in‐Use menu.5 After you have finished adding as much information as you have to the rule, click Save, let thepolicy and rule run, and tune as needed.Identify insider threats by deploying a standard policyIf you are trying to prevent damage from insider threats, you can monitor network traffic using theEmployee Discontent policy.Before you beginOn the Policy page, check the status of the Employee Discontent policy. It should be set toActive, and all of the rules within it should be Enabled. If you are monitoring insiders whohave accounts on a directory server, it should be registered to <strong>McAfee</strong> DLP Manager.Depending on what you know about employee morale, you might modify the rules in the policy totarget a single business unit — or edit the DISCONTENT concept to include specific language youmight expect to find in employee communications.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies | Concepts.• On your <strong>McAfee</strong> DLP appliance, select Policies | Concepts.2 Open the Acceptable Use category and click DISCONTENT.3 Add, modify, or delete expressions using the existing regular expression patterns, then Save.4 In the page header, click Policies.5 Open the Employee Discontent policy, then the Disgruntled Employee Communications rule.The Edit Rule page appears.6 Open the Source/Destination category and select User Organization from the Elements menu.Review the other elements on the menu to focus on specific email or IP addresses.202 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!