Trellix Device Control controls sensitive content copied to removable devices. Trellix DLP Endpoint also inspects enterprise users’ actions on sensitive content when emailing, using cloud applications, and posting to websites or network shares
The Trellix DLP Endpoint client software is deployed as a Trellix Agent plug-in, and enforces the policies defined in the Trellix DLP policy. It audits user activities to monitor, control, and prevent unauthorized users from copying or transferring sensitive data and generates events recorded by the ePO - On-prem Event Parser.
Events generated by the Trellix DLP Endpoint client software are sent to the ePO - On-prem Event Parser, and recorded in tables in the ePO - On-prem database. Events are stored in the database for further analysis and used by other system components.
Create policies consisting of definitions, classifications, and rule sets (groups of Trellix Device Control, Data Protection, and Discovery rules) in the DLP Policy Manager and Classification consoles in ePO - On-prem.
Deploy the policies to the endpoints.
Collect incidents from the endpoints for monitoring and reporting.
.png)
Trellix DLP Endpoint for Windows safeguards sensitive enterprise information using four layers of protection:
Trellix Device Control rules control information copied to external drives.
Data protection rules control data as it is used or copied to files and emails.
Endpoint discovery scans local file and email repositories for sensitive information.
Web application control rules block specified URLs by name or by reputation.
Trellix DLP Endpoint for Mac safeguards sensitive enterprise information using three layers of protection:
Trellix Device Control rules control information copied to external drives.
Data protection rules control data as it is used or copied to files.
Endpoint discovery scans local file repositories for sensitive information.
Trellix DLP Endpoint safeguards sensitive enterprise information:
Applies policies that consist of definitions, classifications, rule sets, endpoint client configurations, and endpoint discovery schedules.
Monitors the policies and blocks actions on sensitive content, as needed.
Encrypts sensitive content before allowing the action.
Creates reports for review and control of the process, and can store sensitive content as evidence.
You can apply different device and protection rules, depending on whether the managed computer is online (connected to the enterprise network) or offline (disconnected from the network). Some rules also allow you to differentiate between computers within the network and those connected to the network by VPN.