How Trellix DLP Endpoint - SaaS and Trellix Device Control protect sensitive content

Prev Next

Trellix Device Control controls sensitive content copied to removable devices. Trellix DLP Endpoint - SaaS also inspects enterprise users’ actions on sensitive content when emailing, using cloud applications, and posting to websites or network shares.

The Trellix DLP Endpoint - SaaS client software is deployed as a Trellix Agent plug-in, and enforces the policies defined in the Trellix DLP Endpoint - SaaS policy. It audits user activities to monitor, control, and prevent unauthorized users from copying or transferring sensitive data and generates events recorded by the ePO - SaaS Event Parser. Events are stored in a cloud container for further analysis and used by other system components.

  1. Create policies consisting of definitions, classifications, and rule sets (groups of Trellix Device Control, Data Protection, and Discovery rules) in the DLP Policy Manager and Classification consoles in ePO - SaaS .

  2. Deploy the policies to the endpoints.

  3. Collect incidents from the endpoints for monitoring and reporting.

    GUID-39549167-7139-44BE-BFA6-B469A5872813-low.png

You can apply different device and protection rules, depending on whether the managed computer is online (connected to the enterprise network) or offline (disconnected from the network). Some rules also allow you to differentiate between computers within the network and those connected to the network by VPN.