Protecting sensitive data with rules and policies

Prev Next

Create rules to identify sensitive data and take appropriate action.

Rules and rule sets

Rules are made up of conditions, exceptions, and actions. Conditions contain multiple parameters — such as classifications — to define the data or user action to identify. Exceptions specify parameters to exclude from triggering the rule. Actions specify how the rule behaves when a rule is triggered, such as blocking user access, encrypting a file, and creating an incident. Rules are organized into rule sets. A rule set can contain any combination of rule types.

  • Data Protection rules — Data protection rules are used to prevent unauthorized distribution of classified data. When you try to copy classified data, or attach it to an email, Trellix DLP intercepts the attempt and uses the data protection rules to determine which action to take. For example, if the rule action requires a business justification, Trellix DLP Endpoint halts the attempt and displays a dialog box. When the user inputs the justification for the attempt, processing continues.

    • Trellix DLP Endpoint uses several rules to inspect user actions. It scans data-in-use on endpoints and blocks unauthorized transfer of data identified as sensitive or confidential.

    • Trellix DLP Network Prevent uses web and email protection rules to monitor and take action on communication from an MTA server or web proxy server.

    • Trellix DLP Network Monitor can apply the network communication protection, email protection, or web protection rules to analyze supported traffic on your network.

    • Trellix Device Control uses only removable storage data protection rules.

  • Device Control rulesDevice Control rules monitor and potentially block the system from loading physical devices such as removable storage devices, Bluetooth, Wi-Fi, and other plug-and-play devices. Device Control rules consist of device templates and reaction specifications, and can be assigned to specific user groups by filtering the rule with user group definitions.

  • Application control rules — Application control rules block the application rather than blocking the content. For example, a web application control rule blocks a specified URL by name or by reputation.

  • Discovery rulesDiscovery rules are used for file and data scanning. Endpoint Discovery is a crawler that runs on managed computers. It scans the local endpoint file system and the local email (cached) inbox and PST files. Local file system discovery rules define whether the content is to be quarantined, encrypted, content fingerprinted, or have an RM policy or classification applied. Local emails can be quarantined or content fingerprinted. These rules can also define whether an incident is reported, and whether to store the file or email as evidence included in the incident.

    Note

    File system scans are not supported on server operating systems.

    Trellix DLP Discover scans file repositoriesand database repositories and can move or copy filers, apply Rights Management policies to files, and create incidents.

Policies

Policies contain active rule sets and are deployed from ePO - On-prem to the Trellix DLP Endpoint client software, Trellix DLP Discover server, Trellix DLP Network Prevent, or Trellix DLP Network Monitor. Trellix DLP Endpoint policies also contain policy assignment information and definitions.