12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

4Using <strong>McAfee</strong> DLP DiscoverOptimizing scanning with data classificationHow data classification scans work<strong>Data</strong> classification scans can be used as an interim step between Inventory and Discover scans. Theybuild on inventoried data, classifying it by content type and predicting the type of violations that arelikely to be found in the repository.When the results of a classification scan are used as a starting point for new scans, investigation of arepository returns multidimensional results that offer users more ways to protect data and betterresults.Classification scans are especially useful because of their speed and flexibliity. Manifests of filesystems produced by Inventory scans are made up of long lists of data that is difficult andtime‐consuming to analyze. Doing full Discover scans of large repositories might produce so much datathat significant patterns might go unrecognized, and the lack of information about the data might leadto incorrect protection strategies.Classification scans run after repository data has been indexed and before incidents are discovered.This interim step reduces overhead of the scan on the targeted server while increasing the value ofreported results.Currently, the <strong>Data</strong> Classification feature supports only file‐based scans (CIFS, NFS, HTTP, HTTPS, FTP,Documentum, and SharePoint).How categories are used to forecast rule hitsCategories displayed on the Task View page contain rules that could potentially be violated if a Discoverscan were run on that share or repository. By exploring each available option, you can figure out whatcombination of scan parameters will give you the best results.Other attributes include the share, file types, and owners of the classified data. The Measures attributesinclude the number and size of the files that might be discovered.<strong>Data</strong> classification workflowThe <strong>Data</strong> Classification workflow objective is to prepare data found on a repository for optimized scansthat can produce significant results quickly.After you create a classification scan that crawls a specified repository, the classification engine sortsthe scanned data and displays it in graphical form on the <strong>Data</strong> Classification page.<strong>Data</strong> displayed in the Predefined View is made up of any classified data resulting from all scans performedon the <strong>McAfee</strong> DLP Discover appliance.<strong>Data</strong> displayed in the Task View is made up of any classified data resulting from a single scan performedby the <strong>McAfee</strong> DLP Discover appliance. In this view, the sorted data is available for use in subsequentscans by content type (and in the case of a Discover scan, by policy), making it possible to create arefined scan that runs on a very narrow range of data.How classified data is displayedClassified data is displayed in two different views. Predefined Views can be used for common scenarios,and Task Views are user‐configurable.The Predefined View is at the <strong>McAfee</strong> DLP device level, and shows all possible data that has been collectedby various scans. The Task View is at scan task level, and shows data that has been collected by specificscan operations.In the Predefined View , you can use the OLAP Navigator to review many different aspects of the classifieddata. You can examine discovered data in graphical format, export to a report, or save to a CSV fileformat.88 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!