Glossary

Prev Next
Trellix DLP – SaaS terminology

Term

Definition

Action

What a rule does when content matches the definition in the rule. Common examples of actions are block, encrypt, or quarantine.

Crawling

Retrieving files and information from repositories, file systems, and email. Applicable to Trellix DLP Endpoint - SaaS (Discovery)

Classification

Used to identify and track sensitive content and files. Can include content classifications, content fingerprints, registered documents, and ignored text.

Content classification

A mechanism for identifying sensitive content using data conditions such as text patterns and dictionaries, and file conditions such as document properties or file extensions.

Content fingerprinting

A mechanism for classifying and tracking sensitive content. Content fingerprinting criteria specify applications or locations, and can include data and file conditions. The fingerprint signatures remain with sensitive content when it is copied or moved.

Data vector

A definition of content status or usage. Trellix DLP – SaaS protects sensitive data when it is stored (data at rest), as it is used (data in use), and when it is transferred (data in motion).

Definition

A configuration component that makes up a classification.

Device class

A collection of devices that have similar characteristics and can be managed in a similar manner. Device classes apply to Windows computers only, and can have the status

Managed, Unmanaged, or Excluded.

File information

A definition that can include the file name, owner, size, extension, and date created, changed, or accessed.

Use file information definitions in filters to include or exclude files to scan.

Fingerprinting

A text extraction procedure that uses an algorithm to map a document to signatures. Used to create registered documents and for content fingerprinting.

FIPS compliancy

Cryptographic software is configured and used in a way that is compliant with Federal Information Processing Standard 140-2.

Managed devices

A device class status indicating that Trellix Device Control manages the devices in that class.

Match string

The found content that matches a rule.

MTA

Message Transfer Agent or Mail Transfer Agent Software that transfers electronic mail messages from one computer to another using a client–server application architecture.

Path

A UNC name, IP address, or web address. Trellix DLP Endpoint - SaaS (Discovery)

Policy

A set of definitions, classifications, and rules that define how the Trellix DLP – SaaS software protects data.

Redaction reviewer

Allows confidential information in the Protection Workspace to be redacted to prevent unauthorized viewing.

Registered documents

Pre-scanned files from specified repositories. See Fingerprinting.

Manual registration — Signatures of the files are uploaded to ePO - SaaS from Trellix DLP – SaaS when you manually upload files and create a package. These signatures are made available to and downloaded by the endpoints and appliances from the S3 bucket , which are used to track and classify content.

Repository

A folder, server, or account containing shared files.

The repository definition includes the paths and credentials for scanning the data.

Trellix DLP Endpoint - SaaS discovery.

Rule

Defines the action taken when an attempt is made to transfer or transmit sensitive data.

Rule set

A combination of rules.

Scheduler

A definition that specifies scan details and the schedule type, such as daily, weekly, monthly, once, or immediately. Applicable to Trellix DLP Endpoint - SaaS (Discovery)

Strategy

Trellix DLP Endpoint - SaaS divides applications into four categories called strategies that affect how the software works with different applications. In order of Editor, Explorer, Trusted, and Archiver.

Unmanaged devices

A device class status indicating that the devices in that class are not managed by Trellix Device Control. Some endpoint computers use devices that have compatibility issues with the Trellix DLP Endpoint - SaaS device drivers. To prevent operational problems, these devices are set to Unmanaged.

Excluded devices

A device class status indicating that Trellix Device Control does not try to control the devices in that class. Examples are battery devices and processors.