Users whose jobs require routine creation of files that contain sensitive data can be assigned manual classification permission. They can classify the files as they create them as part of their normal workflow.
Users working on Windows or Mac computers with Trellix DLP Endpoint - SaaS can classify files manually. Trellix DLP Discover – SaaS , Trellix DLP Network Prevent – SaaS and Trellix DLP Network Monitor – SaaS rules support files that are classified manually.
In this example, a healthcare provider knows that all patient records must be considered confidential under HIPAA rules. Employees creating or editing patient records are given manual classification permissions.
Create a user group or groups for employees who create or edit patient records.
In ePO - SaaS select Menu → Data Protection → Classification.
On the Definitions tab, select Source/Destination → End User Group.
Select Actions → New Item, replace the default name with a meaningful name such as
PHI User Group, and add users or groups to the definition.Click Save.
Create a PHI (Protected Health Information) classification.
In the Classification module, on the Classification tab, select [Sample] PHI [built-in] in the left pane, then select Actions → Duplicate Classification.
An editable copy of the sample classification appears.
Edit the Name, Description, and Classification Criteria fields as needed.
In the Manual Classification field, click Edit.
In the Additional Actions section, select the classification type.
By default, Manual classification only is selected.
Select Actions → Select End-User Groups.
In the Choose from existing values window, select the group or groups you created previously, then click OK.
Go back to the Classification tab and select Actions → Save Classification.
Employees who are members of the assigned groups can now classify the patient records as they are created. To do so, right-click on the file, select Data Protection, and select the appropriate option.
Note
Only selected options (step 2.d) appear in the menu.