Rules define the action taken when an attempt is made to transfer or transmit sensitive data.
Rule sets can contain four types of rules, data protection, device control, discovery, and application control, though not all rule types are supported by all Trellix DLP products.
Product | Data Protection | Device Control | Discovery | Application Control |
|---|---|---|---|---|
Trellix Device Control | No
| (Same as full endpoint products for Mac and Windows) | No | No |
Trellix DLP Endpoint for Windows | All except mobile protection rules | All | Endpoint discovery rules | All |
Trellix DLP Endpoint for Mac | Application file access, cloud, network share, email (monitoring only)and removable storage protection rules | Plug and play and removable storage protection rules | Endpoint file discovery rules | No |
Trellix DLP Network Monitor | Email, web, and network communication protection rules | No | No | No |
Trellix DLP Network Prevent | Email and web protection rules | No | No | No |
A rule has three parts in addition to the basic rule definition. The basic definition includes the Rule Name, optional Description, drop-down lists to define the State (enabled or disabled) and Severity, and check boxes to define which Trellix DLP product the rule supports. The three parts of the rule — Condition, Exceptions, and Reaction — are defined on separate tabs in the rule definition.
Condition
The condition defines what triggers the rule. For data protection and discovery rules, the condition always includes classification, and can include other conditions. For example, a cloud protection rule contains fields to define the user, cloud service, and the classification. For device control rules, the condition always specifies the user, and can include other conditions such as the device template. Device control rules do not include classifications.
Using classification grouping in a condition — To avoid adding repeated conditions and multiple rule sets, which can cause confusion and administrative overhead, you can group classifications and create a custom expression. When you include multiple classifications in a rule, you can create custom expressions to optimize a condition using the Boolean AND or OR logic.
Exceptions
Exceptions define parameters excluded from the rule. Exceptions have a separate setting to enable or disable them, allowing you to turn the exception on or off when you test rules. Creating an exception definition is optional.
For example, a cloud protection rule can allow specified users and classifications to upload data to the specified cloud services. At the same time, the rule can also block users and classifications defined in the condition section of the rule.
Exception definitions for data protection and discovery rules are similar to condition definitions. The available parameters for exclusion are a subset of the parameters for defining the condition.
Exception definitions for data protection rules are similar to condition definitions. The available parameters for exclusion are a subset of the parameters for defining the condition.
For device control rules, the exception is defined by selecting excluded device templates from a list. The available excluded templates depend on the type of device rule.
Using classification grouping in an exception — To avoid adding repeated conditions and multiple rule sets, which can cause confusion and administrative overhead, you can group classifications and create a custom expression. When you include multiple classifications in an exception of a rule, you can create custom expressions to optimize the exception using the Boolean AND or OR logic.
Reaction
The reaction defines what happens when the rule is triggered. The available actions depend on the type of rule, but the default for all rules is No Action. When selected with the Report Incident option, you can monitor the frequency of rule violations. This procedure is useful for tuning the rule to the correct level to catch data leaks without creating false positives.
The reaction also defines whether the rule is applied outside the enterprise and, for some rules, when connected to the enterprise by VPN.