12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

10Managing action rulesAdd, modify, or delete action rulesAdd, modify, or delete action rulesAdd actions to the list of standard action rules, modify existing ones, or delete them set up <strong>McAfee</strong>DLP Prevent to implement appropriate actions in response to specific policy violations.Tasks• Add action rules on page 224Add action rules to resolve problems when rules generate incidents.• Apply action rules on page 225Apply action rules to rules monitoring data in motion, scanning data at rest, or identifyingsignificant events on endpoints. When an incident is detected, the applied action rule isactivated.• Assign responsibility for actions on page 225Assign responsibility for actions by setting up action rules. For example, reviewers might beassigned to monitor results when incidents are found by a rule containing an action rule.• Change incident status with action rules on page 225Change the status of incidents on the fly by defining action rules that are applied whenthey are found.• Clone action rules on page 226Clone action rules to use the same actions in another rule.• Delete action rules on page 226Delete action rules individually or in groups.• Modify action rules on page 226Modify action rules to serve new purposes.• Log actions taken on page 227If a syslog server has been configured to receive log entries, you can log actions to betaken when a rule hits.• Notify users of actions taken on page 227Notify users of actions taken when incidents are found by setting up email notifications inaction rules.• Reconfigure action rules for web content on page 228You must reconfigure <strong>McAfee</strong> DLP Prevent action rules for use on proxy servers.• Remove actions from rules on page 228Remove actions from rules without affecting other parameters of the rule.Add action rulesAdd action rules to resolve problems when rules generate incidents.Some actions (for example, Block and Encrypt) are cannot be used in the same action rule. If you selectincompatible actions, an error message appears when you attempt to save your changes.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies | Action Rules.• On your <strong>McAfee</strong> DLP appliance, select Policies | Action Rules.2 From the <strong>Data</strong>‐in‐Motion, <strong>Data</strong>‐at‐Rest, or <strong>Data</strong>‐in‐Use Actions menus, select Add Action Rule.The three categories determine where the actions will be implemented — on the network, in arepository, or on an endpoint.3 Type in a name and optional description.224 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!