Removable Storage File Access Device Rule page

Prev Next

Use this page to define a removable storage file access device rule.

Removable storage file access device rules are used to block executables on plug-in devices from running. Because some executables, such as encryption applications on encrypted devices, must be allowed to run, the rule allows you to exclude one application.

Option definitions

Category

Option

Definition

Rule options

Rule name

Enter a unique name for the rule. This field is required.

Description

Click Edit to open the description text box. The maximum description length is 2000 characters. The character counter in the lower left of the window shows the number of characters still available. This field is optional.

State

Select Enabled or Disabled from the drop-down list. You can also change this parameter on the DLP Rule Set page by selecting a rule or rules and selecting Actions Change State. The default is Disabled.

Severity

A relative measure of the gravity of violating this rule. The default is Warning. The color code that also appears in the DLP Incident Manager is displayed next to the field.

Enforce On

Selects the Trellix DLP product enforcing the rule. Removable storage file access device rules are enforced on Trellix DLP Endpoint for Windows only.

Condition tab

End-User

Select a user group from the drop-down list. Using the + icon, you can select multiple groups using AND/OR logic. You can exclude groups using the Exceptions tab. Include at least one group before excluding any groups.

Removable Storage

Select a defined removable storage device, or create a definition. This field is required.

True File Type

Select a true file type definition (built-in), or create your own.

Note

This field has a default entry that you can edit as required.

File Extension

Select the executables to block.

Note

This field has a default entry that you can edit as required.

File Name

Select an executable to exclude from the definition.

Exceptions tab

Note

The Exceptions tab is optional.

In the left pane, select:

  • Excluded Device Definitions

  • Excluded File Names

  • Excluded Users

Name

Enter a unique name for the exception. This field is required.

Description

Optional descriptive text.

State

Select Enabled or Disabled from the drop-down list. The exception state is independent from the rule state.

Removable Storage

Select a defined removable storage device to exclude from the rule.

File Name

Select a file name list to exclude from the rule.

End-User

Select a user group to exclude from the rule.

Reaction tab

Trellix DLP Endpoint

Data protection and device protection rules have a granular Action definition. You can define different actions for the following:

  • Computer connected to corporate network

  • Computer disconnected from the corporate network

Action

Select an action from the drop-down list. The default is No Action.

Note

Selecting No Action with Report Incident is sometimes referred to as Monitor.

For a list of prevent actions for different types of rules, see the available reactions table.

User Notification

User notification definitions are stored in the DLP Policy in the Policy Catalog. Select a predefined definition, or click New Item to create one.

Report Incident

Select the checkbox for the rule to trigger a DLP incident.