12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3Managing3<strong>McAfee</strong> DLP Prevent<strong>McAfee</strong> DLP Prevent provides protection for email, webmail, chat, webposts, and other types ofcontent transmitted via SMTP or ICAP. By analyzing communications forwarded from email or proxyservers, marking detected policy violations, and returning processed messages to the appliance, whichexecutes the preventive, corrective, or protective actions.A single rule can have one of each of the three action rule types so that the parameters of any rulecan be applied to <strong>Data</strong>‐in‐Motion, <strong>Data</strong>‐at‐Rest, or <strong>Data</strong>‐in‐Use. Each action rule can be configured toautomatically notify users that a preventive, corrective, or protection action has been applied. It mightalso include parameters that place a record of the incident or event in a system log, assign it to one ormore reviewers, or apply a status to an incident or case that indicates its stage of resolution.<strong>McAfee</strong> DLP Prevent uses multi‐threaded processing, which allows SMTP or ICAP traffic to pass quicklythrough the monitor port, decreasing response time and enhancing performance.ContentsHow <strong>McAfee</strong> DLP Prevent can be usedHow <strong>McAfee</strong> DLP Prevent worksConfiguring <strong>McAfee</strong> DLP PreventHow <strong>McAfee</strong> DLP Prevent can be usedTo get a general understanding of how <strong>McAfee</strong> DLP Prevent can be used to resolve policy violations inSMTP and ICAP traffic, edit <strong>Data</strong>‐in‐Motion action rules.Use <strong>McAfee</strong> DLP Prevent to capture network traffic for later forensic analysis or block the transmissionof sensitive data sent using specific mail protocols (for example, HTTP POST, SMTP_Request, etc.)When violations are found in network email, <strong>McAfee</strong> DLP Prevent is used with action rules to controldata in motion on the network. To implement a range of actions, you can combine several action ruleparameters in one rule:• Block confidential data breaches• Encrypt authorized transmissions• Monitor traffic, allowing email but still generating incidents• Quarantine suspicious traffic• Bounce email that violates policies• Notify supervisory personnel• Record incidents in a system log<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 65

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!