12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

9Managing policies and rulesManage rulesView rule parametersView rule parameters by opening the policy the rule is filed under, then opening the rule.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies | Policies.• On your <strong>McAfee</strong> DLP appliance, select Policies | Policies.2 Click a Policy Name to open the Edit Policy page.3 Click a Rule name to open the Edit Rule page.4 Open the categories under the Define, Actions, and Exceptions tabs.5 If no changes are warranted, click Cancel.Tune rulesTune rules by testing them on historical data before applying them to data captured in real time. Bytesting each rule before its policy is applied, you can eliminate parameters that produce falsepositives.Click on a policy in the Group by window and examine the incidents reported by its rules. Click Details foran incident to determine the rule that produced it, then edit the rule to produce better results.The Test Rule button is available only when tuning rules, because the test uses only historical data. TheTune Rules button is available on the Incidents dashboard or the Incident Details page.During the process, you might want to analyze the performance of the rule by clicking on the Chart andCompare charts. These tools will help you to understand how the rule results fit into the trend and theperformance of the other rules.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Reporting | Incidents.• On your <strong>McAfee</strong> DLP appliance, select Incidents.2 Click on a rule in the Group by window and evaluate its existing incidents.3 When you find one that is delivering a false positive, click Details and make a note of the policy andrule that produced the incident.You can select all incidents produced by the rule and tune them in a single operation by selectingthe Tune Rule.4 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies.• On your <strong>McAfee</strong> DLP appliance, select Policies.5 Click on the policy, then the rule.The Edit Rule page appears.6 Set the Inherit Policy State to Disabled so you can run the rule without the other rules in the policy.214 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!