Policy workflow to protect sensitive data

Prev Next

Trellix DLP – SaaS products use a similar workflow for creating policies. A policy consists of rules, grouped into rule sets. Rules use classifications and definitions to specify what Trellix DLP – SaaS detects. Rule reactions determine the action to take when data matches the rule.

Use this workflow for creating and applying policies:

How policy components make up a policy


GUID-C8BB40FF-4432-4D9E-99F4-5591DCF6C92A-low.png

1

Create definitions — Used to create classifications and rules.

2

Create a classification — Define categories of sensitive data by creating classifications. Classifications are used by rule sets to define the data protection rule.

  • Content fingerprinting criteria and ignored text — Supported in Trellix DLP Endpoint - SaaS for Windows only.

  • Registered documents — Created in the Classification console (manual registration) for Trellix DLP Endpoint - SaaS for Windows clients and Trellix DLP – SaaS appliances.

  • Create classification criteria — Used to create definitions to identify sensitive text patterns, dictionaries, and keywords. Not supported with Trellix Device Control – SaaS.

3

Create a rule set and Create a rule — Rule sets can combine multiple data protection rules for improved coverage of data protection. Create a rule and its actions and add it to a rule set.

4

Assign rule sets to policies — A policy can have multiple rule sets. Before you apply rule sets to a policy, activate the rule sets. Assign the rule sets to the policy and then apply the required rule sets to the policy.

5

Assign and push a policy to a systemTrellix DLP – SaaS policies are assigned to endpoints and Trellix DLP – SaaS appliances from System Tree. You can use the Wake Up Agents option or the Break inheritance and assign the policy and settings below option to push a policy to a system.

The options and availability for these components vary depending on which Trellix DLP – SaaS product you use.