12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3Managing <strong>McAfee</strong> DLP PreventConfiguring <strong>McAfee</strong> DLP PreventPreventive, corrective, and protective actionsThe networked <strong>McAfee</strong> DLP products offer a variety of different responses when significant incidents orevents are detected. Each type of action acts on a different type of data.Table 3-1 <strong>McAfee</strong> DLP actions by product<strong>Product</strong> <strong>Data</strong> type Available actions Role in networked DLP suite<strong>McAfee</strong> DLPPrevent<strong>McAfee</strong> DLPMonitor<strong>McAfee</strong> DLPDiscover<strong>McAfee</strong> DLPEndpoint Host<strong>Data</strong> in Motion Allow, Block, Bounce,Encrypt, Monitor,Notify, Quarantine,Redirect<strong>Data</strong> in Motion Allow<strong>Data</strong> at Rest<strong>Data</strong> in UseMove, Copy, Encrypt,DeleteBlock, Delete, Encrypt,Monitor, Notify,Quarantine, RequestJustification, StoreEvidence, TagEvaluates email and webmail that hasbeen forwarded from an MTA or proxyserver, marks messages that violateactive rules with certain actions, andpasses them back to the mail servers tobe enforced.Captures, monitors, analyzes, and detectsviolations by applying rules to or queryingdata in network traffic.Executes remedial actions when sensitiveor registered content is detected in anetwork repository or database.Protects endpoint data and devices withspecific actions that can be deployed onoroff‐site when violations are found.Implementation of actions in a unified policy systemIn a managed system including <strong>McAfee</strong> DLP Monitor, <strong>McAfee</strong> DLP Discover, and <strong>McAfee</strong> DLP Endpoint,every rule can be configured to deploy one action of each of the three data types (<strong>Data</strong>‐in‐Motion,<strong>Data</strong>‐at‐Rest, <strong>Data</strong>‐in‐Use).When <strong>McAfee</strong> DLP Prevent is added to a <strong>McAfee</strong> DLP Manager managed system, it is used toimplement remedial actions and protection rules defined by <strong>McAfee</strong> DLP Discover and <strong>McAfee</strong> DLPEndpoint as well as all actions appended to <strong>McAfee</strong> DLP Monitor rules.<strong>McAfee</strong> DLP Monitor is a passive component on the network, so it allows all traffic by default. Except forALLOW, <strong>McAfee</strong> DLP Monitor cannot implement <strong>Data</strong>‐in‐Motion Prevent policy actions unless <strong>McAfee</strong> DLPPrevent is added to the system.Configuring <strong>McAfee</strong> DLP PreventTo configure <strong>McAfee</strong> DLP Prevent, set it up with an Mail Transfer Agent (MTA) or proxy server, thenallow rules that find policy violations to apply pre‐configured actions.Requirements for configuring MTAs with <strong>McAfee</strong> DLP PreventBefore you set up an MTA to interoperate with <strong>McAfee</strong> DLP Prevent, you must determine if it meets theminimum requirements.• The email server must be capable of sending outgoing traffic to the <strong>McAfee</strong> DLP Preventapplication. In some environments, only a portion of SMTP traffic might need to be scanned. Forexample, only messages with attachments or those that are directed to public sites (such as Gmail)might be directed to the Prevent appliance.• The email server must be capable of inspecting headers of incoming messages.• The email server must be capable of acting on header strings in email headers — specifically,X‐RCIS‐Action headers with values ALLOW, BLOCK, QUART, ENCRYPT, BOUNCE, REDIR and NOTIFY.68 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!