Edit Permission Set: Data Loss Prevention page

Prev Next

Permission set options are designed to give granular control over administrator roles.

While the division of roles is optional, if you are using the sensitive data redaction feature, you must create separate permission sets for the monitor viewer and the administrator who can reveal the encrypted data. To assign Permission sets, go to MenuUser ManagementPermission Sets and edit Data Loss Prevention permission sets.

Option definitions

Category

Option

Definition

Policy Catalog

N/A

Users can view any Trellix DLP policy. Users can edit policies if they are an owner or if they are a member of the global administrator permission set.

DLP Discover

Discover Permissions

Select to have full control over configuring and running scans.

Note

Users must have DLP Policy Manager permissions to use rule sets in remediation scans.

DLP Policy Manager

Rule Sets Access Control

Select Use permissions to select rule sets for use in policies and scans.

Select View and use permissions to select rule sets for use in policies and scans and view details of rule sets and rules.

Select Full permissions to use, view, create, modify, and delete rule sets and rules.

Override permission for specific rule sets

Select a permission level for a specific rule set to override the inherited permission.

Rule Types

Checkboxes for data protection, device control, and discovery rules. Sets the rule types that are available.

Classifications

Classification Actions

Select Manage manual classifications to manage manual classifications.

Select Registered documents and ignored text to upload files for registering documents or ignorning text.

Classification Permissions

Select Use permissions to select classifications for use in rules and view classification and tagging criteria.

Select View and use permissions to select classifications for use in rules.

Select Full permissions to use, view, create, modify, and delete classifications.

Override permission for specific rule sets

Select a permission level for a specific classification to override the inherited permission.

Definitions

Definition Permissions

Select use to select the definition in classifications, rules, and policies.

Select view and use to select the definition in classifications, rules, and policies, and can view definition content.

Select full access to use, view, create, modify, and delete definitions.

Incident Management

Incident Access by Type

Deselect rule types to limit access to only those types selected.

Incident Access by Reviewer (advanced)

Select Users can view and edit incidents assigned to them to view and edit incidents assigned to the owner. If redaction is selected, sensitive fields are blocked.

Select Users can view and edit incidents assigned to the following permission sets to view and edit incidents assigned to the selected permission sets. If redaction is selected, sensitive fields are blocked.

Click ... to select one or more permission sets.

Select User can view and edit all incidents to view and edit all incidents regardless of the assignment. If redaction is selected, sensitive fields are blocked.

Select User can view incidents assigned to them to view incidents assigned to the owner. If redaction is selected, sensitive fields are blocked.

Select User can view incidents assigned to the following permission sets to view incidents assigned to the selected permission sets. If redaction is selected, sensitive fields are blocked.

Click ... to select one or more permission sets.

Select User can view all incidents to view all incidents regardless of assignment. If redaction is selected, sensitive fields are blocked.

Evidence File Access

Select options to view evidence files or match string files or both.

Incidents Data Redaction

Select Supervisor permission to only reveal redacted fields when the incident is opened by a reviewer with access to the file.

Select Obfuscate sensitive incidents data to encrypt sensitive data so that it is not visible to the reviewer. This is considered a best practice.

Incident Tasks

Select User can create a Mail Notification task to create a task that sends email notification of policy violations.

Select User can create a Purge notification task to create a task that notifies recipients of an upcoming database purge.

Select User can create a Set Reviewer task to create a task that assigns reviewers to incidents.

REST API

Select User can view the contents of evidence files through REST API to allow use of the REST API option.

Operational Events

Operational Reviewer

Select User can view operational events assigned to him to view operational events assigned to a user. If redaction is selected, sensitive fields are blocked.

Select User can view operational events assigned to the following permission sets to view operational events assigned to the selected permission sets. If redaction is selected, sensitive fields are blocked.

Click ... to select one or more permission sets.

Select User can view all operational events to view all operational events regardless of assignment. If redaction is selected, sensitive fields are blocked.

Operational Tasks

Select User can create a Mail Notification task to create a task that sends email notification of policy violations.

Select User can create a Purge notification task to create a task that notifies recipients of an upcoming database purge.

Select User can create a Set Reviewer task to create a task that assigns reviewers to incidents.

Case Management

Owner

Select User can view cases assigned to him to view cases assigned to the user. If redaction is selected, sensitive fields are blocked.

Select User can view cases assigned to the following permission sets to view cases assigned to the selected permission sets. If redaction is selected, sensitive fields are blocked.

Click ... to select one or more permission sets.

Select User can view all cases to view all cases regardless of assignment. If redaction is selected, sensitive fields are blocked.

DLP Settings

DLP Settings Tabs

Deselect tabs to limit the DLP Settings users can access.

Capture

Capture Permissions

Allows the user to work with captured content to look for previously unidentified data loss incidents, save results as incidents and add them to cases, and tune rules or classification settings without affecting your live data analysis.