How Trellix DLP works with rights management

Prev Next

Trellix DLP follows a workflow to apply RM policies to files.

RM workflow

  1. Create and apply a data protection or a discovery rule with a reaction to apply RM policy. The reaction requires an RM server, and an RM policy entry.

  2. When a file triggers the rule, Trellix DLP encrypts the file using the selected RM server.

  3. The RM server applies protections based on the specified policy, such as encrypting the file, limiting the users allowed to access or decrypt the file, limiting the users allowed to read or access labeled files, and limiting the conditions in which the file can be accessed.

  4. The RM server sends the file back to the source with the applied protections.

  5. If you have configured a classification for the file, Trellix DLP can monitor the file.

Limitations

Trellix DLP Endpoint software does not inspect RM protected files for content. When a classification is applied to a file that is RM protected, only content fingerprint criteria (location, application, or web application) are maintained. If a user modifies the file, all fingerprint signatures are lost when the file is saved.