Create a rule with classification grouping

Prev Next

Use the generic steps in this process to create a rule and its actions, and add it to a rule set. The steps can apply to all rule types.

  1. In ePO - On-prem, select MenuData ProtectionDLP Policy Manager.

  2. Click the Rule Sets tab.

  3. Click the name of a rule set and if needed, select the appropriate tab for the Data Protection, Device Control, Discovery, or Application Control rule.

  4. Select ActionsNew Rule, then select the type of rule.

  5. On the Condition tab, enter the information.

    • For some conditions, such as Classification or device template items, click ... to select an existing item or create an item and click + to include additional criteria. An item number is assigned to each row that is included.

      Using classification grouping condition — You can fine-tune a condition set with different classifications and further customize the condition by grouping the classifications. When you include multiple classifications in a rule you can group classifications and create a custom expression to optimize a condition using the Boolean AND or OR operations. For example, if classifications 1, 2, and 3 are included in a Classification condition, you can create an expression similar to ((1 AND 2) OR (1 AND 3)).

      When more than two rows of conditions are included, a toggle button appears. Click the toggle button to enable classification grouping. The expressions are simplified using the Boolean logic. The brackets are added automatically to the expression if not included. If an expression has both AND and OR operations, the classification item numbers with AND logic are grouped first and then the classification item numbers with OR logic are grouped. The AND operation takes precedence over the OR operation and the expression is computed from left to right. The classification grouping expression must include all classification item numbers that are assigned to each classification.

    • In the End User drop-down, for the belongs to one of end-user groups (OR) or belongs to all following end-user groups (AND) options, click ... to select an existing group or to create a new group.

    • To include additional criteria, click +.

    • To remove a criteria, click .

  6. (Optional) To add exceptions to the rule, click the Exceptions tab.

    1. Select ActionsAdd Rule Exception.

      Device rules do not display an Actions button. To add exceptions to device rules, select an entry from the displayed list.

    2. Fill in the fields as needed.

      Using classification grouping in an exception — You can fine-tune an exception set with Classification and further customize the exception by grouping the classifications. When you include multiple classifications in a rule, an item number is assigned to each row that is included. You can create a custom expression to optimize a condition using the Boolean AND or OR operations. For example, if classifications 1, 2, and 3 are included in Classification, you can create an expression similar to ((1 AND 2) OR (1 AND 3)).

      When more than two rows of classifications are included, a toggle button appears. Click the toggle button to enable custom classification grouping. The expressions are simplified using the Boolean logic. The brackets are added automatically to the expression if not included. If an expression has both AND and OR operations, the classification item numbers with AND logic are grouped first and then the classification item numbers with OR logic are grouped. The AND operation takes precedence over the OR operation and the expression is computed from left to right. The classification grouping expression must include all classification item numbers.

  7. Depending on your product, configure the Action, User Notification, and Report Incident options on the Reaction tab.

    Rules can have different actions, depending on whether the endpoint computer is in the corporate network. Some rules can also have a different action when connected to the corporate network by VPN.

  8. Click Save.