Use this page to define a Removable Storage Device Rule. Removable storage devices can be blocked, monitored, or set to read-only.
Category | Option | Definition |
|---|---|---|
Rule options | Rule name | Enter a unique name for the rule. This field is required. |
Description | Click Edit to open the description text box. The maximum description length is 2000 characters. The character counter in the lower left of the window shows the number of characters still available. This field is optional. | |
State | Select Enabled or Disabled from the drop-down list. You can also change this parameter on the DLP Rule Set page by selecting a rule or rules and selecting Actions → Change State. The default is Disabled. | |
Severity | A relative measure of the gravity of violating this rule. The default is Warning. The color code that also appears in the DLP Incident Manager is displayed next to the field. | |
Enforce On | Selects the Trellix DLP product enforcing the rule. The default is to enforce on both Trellix DLP Endpoint for Windows and Trellix DLP Endpoint for Mac. | |
Condition tab
| End-User | Select a user group from the drop-down list. Using the + icon, you can select multiple groups using AND/OR logic. You can exclude groups using the Exceptions tab. Include at least one group before excluding any groups. |
Removable Storage | Select a defined removable storage device, or create a new definition. This field is required. | |
Exceptions tab
In the left pane, select a definition to:
| Name | Enter a unique name for the exception. This field is required. |
Description | Optional descriptive text. | |
State | Select Enabled or Disabled from the drop-down list. The exception state is independent from the rule state. | |
Removable Storage | Select a defined removable storage device to exclude from the rule. | |
Process Name (Windows only) | Select a process name definition to exclude from the rule. | |
Serial Number & User Pairs (Windows only) | Select a serial number and user pair definition to exclude from the rule. | |
End-User | Select a user group to exclude from the rule. | |
Reaction tab DLP Endpoint Data protection and device protection rules have a granular Action definition. You can define different actions for the following:
| Action | Select an action from the drop-down list. The default is No Action.
For a list of prevent actions for different types of rules, see the available reactions table. |
User Notification | User notification definitions are stored in the DLP Policy in the Policy Catalog. Select a predefined definition, or click New Item to create one. | |
Report Incident | Select the checkbox for the rule to trigger a DLP incident. |