McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide McAfee Data Loss Prevention 9.2.2 Product Guide

kb.mcafee.com
from kb.mcafee.com More from this publisher
12.07.2015 Views

4Using McAfee DLP DiscoverTypical scenariosTask1 Select one of these options:• In ePolicy Orchestrator, select Menu | Data Loss Prevention | DLP Policies | Registered Documents.• On your McAfee DLP appliance, select Policies | Registered Documents.2 From the Actions menu, select Upload New File.3 Browse to locate a sensitive file that must be protected.Mozilla Firefox 3.5 will not include the path to the uploaded document unless you reconfigure itbefore scanning.4 Select a policy and rule to guide the search.For example, select the Financial and Security Compliance policy and the Financial StatementDocuments rule to protect a document that contains sensitive financial information.5 If more documents need protection, select Save & Upload Another and repeat the process.6 Click Save.7 After some time, check the Data‐at‐Rest vector on your McAfee DLP Manager dashboard. For fullcoverage, add the content to a rule and schedule it to run at regular intervals.Remember to select an appropriate time filter. The system cannot track data before it wasuploaded.Control copies of sensitive documentsConfidential documents often proliferate over networks, because employees can copy or move them toinsecure locations to work on them, or share them with other staff members. You can find sensitivedocuments that have been copied or moved by using their signatures.Task1 Create a Discover scan to find the file on the targeted repository.The scan will produce a list of incidents on the Data‐at‐Rest dashboard.2 Select one of these options:• In ePolicy Orchestrator, select Menu | Data Loss Prevention | DLP Reporting | Incidents.• On your McAfee DLP appliance, select Incidents.3 Select Data‐at‐Rest from the vector thumbwheel and click Columns.4 Add the Signature and Path columns to your dashboard, then click Apply.5 Select one of these options:• In ePolicy Orchestrator, select Menu | Data Loss Prevention | DLP Policies | Registered Documents.• On your McAfee DLP appliance, select Policies | Registered Documents.6 On the Web Upload page, click View to locate the signature number, and copy it.7 Select one of these options:• In ePolicy Orchestrator, select Menu | Data Loss Prevention | DLP Reporting | Advanced Search.• On your McAfee DLP appliance, select Capture | Advanced Search.74 McAfee Data Loss Prevention 9.2.2 Product Guide

Using McAfee DLP DiscoverRegistering documents and structured data 48 Open the File Information category and select Signature | is any of , then paste the signature number inthe value field.9 Click Search.All incidents containing the file with that unique signature will be reported to the dashboard.10 View the Signature and Path columns, which will tell you the exact locations of the file.Registering documents and structured dataData in documents and databases can be registered by uploading files or structured data or by using aRegistration scan to create signatures for many files in a defined location. You can also register filesusing a McAfee DLP Discover scan to match rules to data at rest to tag sensitive data, embedsignatures in rules that run on a regular basis, or deploy signatures to endpoints through McAfee DLPAgent.Signatures that identify registered data are stored in two factory default concepts:• DocReg — Document registration for unstructured data• DBReg — Data registration for structured dataThe content of these two concepts can be accessed by adding them as components to rules that areused to crawl repositories during a Discover scan.For McAfee DLP Endpoint scans, the signatures are stored in registered document packages that aredeployed to endpoints.When data is registered by the web upload method, all devices registered to McAfee DLP Manager atthat time will receive the signatures. When data is registered by scanning, you can choose the devicethat will store the signatures.There are four ways to register content:• Uploading files or structured data• Applying policies to data at rest in repositories• Using signature collections (DocReg or DBReg) or signatures created with a SHA‐2 sum utility inrules• Scanning endpoints and deploying the signature package to McAfee DLP AgentSignatures that identify sensitive data are generated by complex algorithms during a registration scanor by uploading documents. Each protected document might contain hundreds of overlappingsignatures, which are expressed as hexadecimal numbers. The density, or fidelity, of the signaturetiling depends on the level of detection needed.Typically, the registration process runs whenever a document is uploaded to a McAfee DLP Discoverappliance, or when a Registration scan runs on a designated file system or database.Types of signaturesThe signature type selected when data is registered determines the density of signatures generatedduring registration.Signature types vary depending on usage and available memory.McAfee Data Loss Prevention 9.2.2 Product Guide 75

Using <strong>McAfee</strong> DLP DiscoverRegistering documents and structured data 48 Open the File Information category and select Signature | is any of , then paste the signature number inthe value field.9 Click Search.All incidents containing the file with that unique signature will be reported to the dashboard.10 View the Signature and Path columns, which will tell you the exact locations of the file.Registering documents and structured data<strong>Data</strong> in documents and databases can be registered by uploading files or structured data or by using aRegistration scan to create signatures for many files in a defined location. You can also register filesusing a <strong>McAfee</strong> DLP Discover scan to match rules to data at rest to tag sensitive data, embedsignatures in rules that run on a regular basis, or deploy signatures to endpoints through <strong>McAfee</strong> DLPAgent.Signatures that identify registered data are stored in two factory default concepts:• DocReg — Document registration for unstructured data• DBReg — <strong>Data</strong> registration for structured dataThe content of these two concepts can be accessed by adding them as components to rules that areused to crawl repositories during a Discover scan.For <strong>McAfee</strong> DLP Endpoint scans, the signatures are stored in registered document packages that aredeployed to endpoints.When data is registered by the web upload method, all devices registered to <strong>McAfee</strong> DLP Manager atthat time will receive the signatures. When data is registered by scanning, you can choose the devicethat will store the signatures.There are four ways to register content:• Uploading files or structured data• Applying policies to data at rest in repositories• Using signature collections (DocReg or DBReg) or signatures created with a SHA‐2 sum utility inrules• Scanning endpoints and deploying the signature package to <strong>McAfee</strong> DLP AgentSignatures that identify sensitive data are generated by complex algorithms during a registration scanor by uploading documents. Each protected document might contain hundreds of overlappingsignatures, which are expressed as hexadecimal numbers. The density, or fidelity, of the signaturetiling depends on the level of detection needed.Typically, the registration process runs whenever a document is uploaded to a <strong>McAfee</strong> DLP Discoverappliance, or when a Registration scan runs on a designated file system or database.Types of signaturesThe signature type selected when data is registered determines the density of signatures generatedduring registration.Signature types vary depending on usage and available memory.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 75

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!