Classifying files manually

Prev Next

Users can manually apply or remove classifications or content fingerprinting to files.

The manual classification feature applies file classification. That is, the classifications applied do not need to be related to content. For example, a user can place a PCI classification on any file even if the file does not contain credit card numbers. Manual classification is embedded in the file. In Microsoft Office files, the classification is stored as a document property and as a clear text in header, footer, and watermark. In other supported files, it is stored as an XMP property. For email, it is added as markup text.

When setting up manual classification, you can also allow a user to manually apply content fingerprints.

Trellix DLP offers two types of support for manual classifications: one for Microsoft Office files, and one for all supported file types:

  • Trellix DLP Endpoint - SaaS can customize visual labels for appearance and classify files and emails manually in Microsoft Office and Outlook documents. Visual labels allow you to communicate sensitivity levels of files to end users with the customization of styles, such as borders, fonts, and contextual metadata. The end users can clearly understand the document or email sensitivity while complying with the regulatory standards.

  • Trellix DLP Endpoint - SaaS clients (on both Windows and Mac endpoints), Trellix DLP Network Prevent – SaaS, and Trellix DLP Network Monitor – SaaS can detect manually classified files (in email attachments, for example) and take appropriate action based on the classification.

  • Trellix DLP Discover – SaaS can detect manual classifications in classification and remediation scans, and can take appropriate action in remediation scans.

By default, users do not have permission to view, add, or remove classifications, but you can assign specific classifications to specific user groups, or to everyone. The assigned users can then apply the classification to files as they work. Manual classification can also allow you to maintain your organization’s classification policy even in special cases of sensitive or unique information that the system does not process automatically.

When setting up permission for manual classification, you have the option of allowing content classifications, content fingerprints, or both to be applied manually.

Managing manual classifications in Microsoft Office

For Microsoft Word, Excel, PowerPoint, and Outlook, manual classification with visual labeling is supported when the file is created or with email communication.

  • Labeling or tagging files — End users can click the Manual Classification icon in Microsoft Office applications to apply visual labeling and classifying files.

  • Enforcement — Administrators can set options in Trellix DLP Endpoint - SaaS to force end users to classify or label files by activating the manual classification pop-up when they save files or send messages.

  • Customizing and selection control — Administrators can customize the appearance of visual labels in Policy CatalogWindows Client ConfigurationUser Interface ComponentsVisual Labeling. Options include setting borders, border size, and changing fonts. You can limit users to a single classification selection by unchecking the Allow end users to... checkbox.

  • Dual LabelingTrellix DLP Endpoint - SaaS supports applying secondary classification labels to the required Microsoft Office files.

Manual classification of an email is relevant for a specific thread only. If you send the same email twice in different threads, you have to classify it twice. For emails, information can only be added to the header or footer as a visual label (set on the manual classification General Settings page).

Note

For Microsoft Office documents independent selection of Classify option is supported.

Classify all supported file types from Windows Explorer or Mac Finder using the right-click (Mac Ctrl-click) menu.

GUID-E7681663-DCF6-4B24-95FE-D55EE6A28FCF-low.png
Configuring manual classification with customizable visual labels

Administrators allow end users to apply visual labels and classify files and Microsoft Outlook emails. Administrators can also enforce data security policies by requiring user interaction during file saves or email transmissions.

Microsoft Office applications (Word, Excel, and PowerPoint) and Microsoft Outlook are supported at the file creation level. Users can click the manual classification icon, to add visual classification labels and classify files. You can also set options to force users to classify or visual label files by activating the manual classification pop-up when files are saved, or when Outlook emails are sent.

Configuring visual label appearance

Administrators can set the customization for visual label style and format:

  1. In ePO - SaaS, go to Policy CatalogData Loss Prevention <version>.

  2. Click Windows Client Configuration, and select a policy you want to change. Click Edit.

  3. Browse to User Interface Components and in Visual Labeling, update the required values to customize the classification label.

    To apply multiple classifications to the document metadata, select Allow end users to choose one or more classifications to be added to the document metadata.

    You can also apply secondary classification labels for the required Microsoft Office applications.

Supported visual labels style and formatting

Administrators can use any of these styles and formatting with visual labels:

  • Font — font family, font size, styles (bold, all caps), case (upper case, lower case)

  • Text alignment — horizontal (left, centre, right)

  • Border — toggle, color, thickness (0,5pt to 10pt)

  • Dual classification — two classification labels are seen in separate bordered boxes. Dual classification appears in Word only, where primary classification appears in the header with border and same in the footer with border. Secondary classification appears in the header below the primary classification box. In Outlook emails, multiple classifications appear in the header and the same appears at the bottom.

  • Encapsulation — braces (example: {CONFIDENTIAL}, brackets (example: [RESTRICTED], parenthesis (example: (SENSITIVE) )

  • Contextual metadata — You can add:

    Metadata values, such as Data type = PII, Classification Level = HIGH

    Display options - inline with label, appended below label, embedded in documentation/email metadata

Note

Headers and footers are supported in Word, Excel, and Outlook. Only footers are supported in Powerpoint. The body label is only supported in Outlook. For more information, see Applying manual classifications with visual labels for Microsoft Office files and emails.

Limitations

There are some limitations to using visual labeling:

  • Using the right-click menu, you cannot visually label Microsoft Office applications (Word, Excel, and PowerPoint).

  • Documents that are visually labeled by Trellix DLP Endpoint - SaaS can lose visual labeling when a third party visual classification or labels are applied, as the third party tool deletes the original label, which cannot be controlled by Trellix DLP - SaaS.

  • A shared document can overlap with different visual labels when two users add them simultaneously.