USB drives, small external hard drives, smartphones, and other removable devices can be used to remove sensitive data from the enterprise.
USB drives are an easy, cheap, and almost-untraceable method of downloading large amounts of data. They are often considered the "weapon of choice" for unauthorized data transfer. Trellix Device Control software monitors and controls USB drives and other external devices, including smartphones, Bluetooth devices, plug-and-play devices, audio players, and non-system hard disks. Trellix Device Control runs on most Microsoft Windows and macOS operating systems, including servers. See the system requirements page in this guide for details.
Trellix Device Control protection is built in three layers:
Device classes — Collections of devices that have similar characteristics and can be managed in a similar manner. Device classes apply only to plug-and-play device definitions and rules, and are not applicable to macOS operating systems.
Device definitions — Identify and group devices according to their common properties.
Device rules — Control the behavior of devices.
A device rule consists of a list of the device definitions included or excluded from the rule, and the actions taken when use of the device triggers the rule. In addition, it can specify users included or excluded from the rule. They can optionally include an application definition to filter the rule according to the source of the sensitive content.
Removable storage protection rules
In addition to device rules, Trellix Device Control includes one data protection rule type. Removable storage protection rules include one or more classifications to define the sensitive content that triggers the rule. They can optionally include an application definition or web browser URL, and can include or exclude users.
Note
Web browser URLs are not supported on Trellix DLP Endpoint for Mac.