How Trellix DLP – SaaS categorizes applications used in classifications and rule sets can affect system performance.
Note
Categorization is not supported on Trellix DLP Endpoint – SaaS for Mac.
Trellix DLP – SaaS divides applications into four categories called strategies. These affect how the software works with different applications. You can change the strategy to achieve a balance between security and the computer’s operating efficiency.
The strategies, in order of decreasing security, are:
Editor — Any application that can modify file content. This includes “classic” editors like Microsoft Word and Microsoft Excel, and browsers, graphics software, accounting software, and so forth. Most applications are editors. Trellix DLP Endpoint - SaaS client always analyzes files opened or created by editors.
Explorer — An application that copies or moves files without changing them, such as Microsoft Windows Explorer or certain shell applications.
Trusted — An application that needs unrestricted access to files for scanning purposes. Examples are Trellix VirusScan Enterprise or backup software. Use the trusted strategy when you want to make sure that the Trellix DLP Endpoint - SaaS client doesn't analyze files opened or created by the application.
Archiver — An application that can reprocess files. Examples are compression software such as WinZip.
How to work with Trellix DLP – SaaS strategies
Application strategies are set on the Application Template page in DLP Policy Manager → Definitions. Use the built-in templates, or create custom templates.
Change the strategy as needed to optimize performance. For example, the high level of observation that an editor application receives is not consistent with the frequent processing of backup software. The performance penalty is high and the risk of a data leak from such an application is low, so we don't recommend using the trusted strategy with these applications.
You can also create more than one template for an application and assign it more than one strategy. Use the different templates in different classifications and rules to achieve different results in different contexts. You must be careful in assigning such templates within rule sets to avoid conflicts. Trellix DLP – SaaS resolves potential conflicts according to the following hierarchy: archiver > trusted > explorer > editor. That is, editor has the lowest ranking. If an application is an editor in one template and anything else in another template in the same rule set, Trellix DLP – SaaS does not treat the application as an editor.
Trusted strategy versus ignored processes
Trellix DLP – SaaS uses two mechanisms to bypass processing files when no analysis is needed.
Trusted strategy is the general mechanism to use when you want to make sure that files opened or created by the application are not analyzed by the Trellix DLP Endpoint - SaaS client. Use this mechanism for applications that always need unrestricted access to files.
Ignored processes are used to create exceptions to rules. Ignore URL lists create exceptions for web protection rules. You can ignore applications to create exceptions to clipboard and printer protection rules, and to define exceptions for content tracking when creating content fingerprints.