Create rules to identify sensitive data and take appropriate action.
Rules and rule sets
Rules are made up of conditions, exceptions, and actions. Conditions contain multiple parameters — such as classifications — to define the data or user action to identify. Exceptions specify parameters to exclude from triggering the rule. Actions specify how the rule behaves when a rule is triggered, such as blocking user access, encrypting a file, and creating an incident. Rules are organized into rule sets. A rule set can contain any combination of rule types.
Data Protection rules — Data protection rules are used to prevent unauthorized distribution of classified data. When you try to copy classified data, or attach it to an email, Trellix DLP – SaaS intercepts the attempt and uses the data protection rules to determine which action to take. For example, if the rule action requires a business justification, Trellix DLP Endpoint - SaaS halts the attempt and displays a dialog box. When the user inputs the justification for the attempt, processing continues.
Trellix DLP Endpoint - SaaS uses several rules to inspect user actions. It scans data-in-use on endpoints and blocks unauthorized transfer of data identified as sensitive or confidential.
Trellix DLP Network Prevent – SaaS uses web and email protection rules to monitor and take action on communication from an MTA server or web proxy server.
Trellix DLP Network Monitor – SaaS can apply the network communication protection, email protection, or web protection rules to analyze supported traffic on your network.
Trellix Device Control – SaaS uses only removable storage data protection rules.
Device Control rules — Device Control rules monitor and potentially block the system from loading physical devices such as removable storage devices, Bluetooth, Wi-Fi, and other plug-and-play devices. Device Control rules consist of device templates and reaction specifications, and can be assigned to specific user groups by filtering the rule with user group definitions.
Application control rules — Application control rules block the application rather than blocking the content. For example, a web application control rule blocks a specified URL by name or by reputation.
Discovery rules — Discovery rules are used for file and data scanning. Endpoint Discovery is a crawler that runs on managed computers. It scans the local endpoint file system and the local email (cached) inbox and PST files. Local file system discovery rules define whether the content is to be quarantined, encrypted, content fingerprinted, or have an RM policy or classification applied. Local emails can be quarantined or content fingerprinted. These rules can also define whether an incident is reported, and whether to store the file or email as evidence included in the incident.
Note
File system scans are not supported on server operating systems.
Trellix DLP Discover – SaaS scans file repositories and can move or copy files and create incidents.
Policies
Policies contain active rule sets and are deployed from ePO - SaaS to the Trellix DLP Endpoint - SaaS client software, Trellix DLP Discover – SaaS, DLP server, Trellix DLP Network Prevent – SaaS, or Trellix DLP Network Monitor – SaaS. Trellix DLP Endpoint - SaaS policies also contain policy assignment information and definitions.