Defining rules to protect sensitive content

Prev Next

Rules define the action taken when an attempt is made to transfer or transmit sensitive data.

Rule sets can contain four types of rules, data protection, device control, discovery, and application control, though not all rule types are supported by all Trellix DLP – SaaS products.

Product

Data Protection

Device Control

Discovery

Application Control

Trellix Device Control

No

Note

If you have installed Trellix Device Control with content aware removable storage protection, removable storage protection rules are supported.

(Same as full endpoint products for Mac and Windows)

No

No

Trellix DLP Discover – SaaS

No

No

Network discovery rules

No

Trellix DLP Endpoint - SaaS for Windows

All except mobile protection rules

All

Endpoint discovery rules

All

Trellix DLP Endpoint – SaaS for Mac

Application file access, cloud, network share, email (monitoring only)and removable storage protection rules

Plug and play and removable storage protection rules

Endpoint file discovery rules

No

Trellix DLP Network Monitor – SaaS

Email, web, and network communication protection rules

No

No

No

Trellix DLP Network Prevent – SaaS

Email and web protection rules

No

No

No

A rule has three parts in addition to the basic rule definition. The basic definition includes the Rule Name, optional Description, drop-down lists to define the State (enabled or disabled) and Severity, and check boxes to define which Trellix DLP – SaaS product the rule supports. The three parts of the rule — Condition, Exceptions, and Reaction — are defined on separate tabs in the rule definition.

Condition

The condition defines what triggers the rule. For data protection and discovery rules, the condition always includes classification, and can include other conditions. For example, a cloud protection rule contains fields to define the user, cloud service, and the classification. For device control rules, the condition always specifies the user, and can include other conditions such as the device template. Device control rules do not include classifications.

Using classification grouping in a condition — To avoid adding repeated conditions and multiple rule sets, which can cause confusion and administrative overhead, you can group classifications and create a custom expression. When you include multiple classifications in a rule, you can create custom expressions to optimize a condition using the Boolean AND or OR logic.

Exceptions

Exceptions define parameters excluded from the rule. Exceptions have a separate setting to enable or disable them, allowing you to turn the exception on or off when you test rules. Creating an exception definition is optional.

For example, a cloud protection rule can allow specified users and classifications to upload data to the specified cloud services. At the same time, the rule can also block users and classifications defined in the condition section of the rule.

Exception definitions for data protection and discovery rules are similar to condition definitions. The available parameters for exclusion are a subset of the parameters for defining the condition.

Exception definitions for data protection rules are similar to condition definitions. The available parameters for exclusion are a subset of the parameters for defining the condition.

For device control rules, the exception is defined by selecting excluded device templates from a list. The available excluded templates depend on the type of device rule.

Using classification grouping in an exception — To avoid adding repeated conditions and multiple rule sets, which can cause confusion and administrative overhead, you can group classifications and create a custom expression. When you include multiple classifications in an exception of a rule, you can create custom expressions to optimize the exception using the Boolean AND or OR logic.

Reaction

The reaction defines what happens when the rule is triggered. The available actions depend on the type of rule, but the default for all rules is No Action. When selected with the Report Incident option, you can monitor the frequency of rule violations. This procedure is useful for tuning the rule to the correct level to catch data leaks without creating false positives.

The reaction also defines whether the rule is applied outside the enterprise and, for some rules, when connected to the enterprise by VPN.