How remediation scans work

Prev Next

Use the results of inventory and classification scans to build remediation scans.

Remediation scans apply rules to protect sensitive content in the scanned repository. When data matches the classification in a remediation scan, Trellix DLP Discover can perform the following:

Action

When scanning a file repository

When scanning a database

Generate an incident

x

x

Store the original file/table in the evidence share

x

x

Copy the file

x

Move the file

x

Note

Box and SharePoint scans support moving files only to SMB/CIFS shares.

Apply RM policy to the file

x

Classify file as

x

Remove automatic classification

x

Modify anonymous share to login required.

Box scans only

Note

Trellix DLP Discover cannot prevent Box users from reenabling external sharing on their files.

Take no action

x

x

Note

Moving files or applying RM policy to files is NOT supported for SharePoint lists. These actions are supported for files attached to SharePoint lists or stored in document libraries. Some file types used for building SharePoint pages, such as .aspx or .js cannot be moved or deleted.

A remediation scan also performs the same tasks as inventory and classification scans. Remediation scans require classifications and rules to determine the action to take on matched files.

The results of remediation scans are displayed on the Data Inventory and Data Analytics tabs. Remediation scans can also generate incidents displayed in the Incident Manager .