Removable Storage Protection rule page

Prev Next

Removable storage protection rules block data from being written to removable storage devices, including mobile devices using the Media Transfer Protocol (MTP).

To protect devices using MTP, verify that the Removable Storage ProtectionPortable Devices Handler is activated in the Policy Catalog client configuration on the Operational Mode and Modules page.

Option definitions

Category

Option

Definition

Rule options

Rule name

Enter a unique name for the rule. This field is required.

Description

Click Edit to open the description text box. The maximum description length is 2000 characters. The character counter in the lower left of the window shows the length of the entry. This field is optional.

State

Select Enabled or Disabled from the drop-down list. You can also change this parameter on the DLP Rule Set page by selecting a rule or rules and selecting ActionsChange State. The default is Disabled.

Severity

A relative measure of the gravity of violating this rule. The default is Warning. The color code that also appears in the DLP Incident Manager is displayed next to the field.

Enforce on

Selects the Trellix DLP product enforcing the rule. The default is to enforce on both Trellix DLP Endpoint for Windows and Trellix DLP Endpoint for Mac.

Condition tab

Note

All fields in this section are required. The default ALL can be used instead of a defined parameter.

Classification

Use the is any data (ALL) option to bypass applying a content classification, or use the is one of (OR) or is all of (AND) options to select predefined classifications. You can use the + icon to add multiple classifications, and define their relationship with the and/or option.

Using classification grouping — When you include multiple classifications in a rule, you can group classifications and create a custom expression to optimize a condition using the Boolean AND or OR operations. When more than two rows of conditions are included, a toggle button appears. Click the toggle button to enable custom classification grouping and type the custom classification grouping expression. For example, if classifications 1, 2, and 3 are included in a Classification condition, you can build an expression similar to ((1 AND 2) OR (1 AND 3)).

The expressions are simplified using the Boolean logic. The brackets are added automatically to the expression if not included. If an expression has both AND and OR, the classification item numbers with AND logic are grouped first and then the classification item numbers with OR logic are grouped. The AND operation takes precedence over the OR operation and the expression is computed from left to right. A classification grouping expression must include all classification item numbers.

End-User

Select a user group from the drop-down list. Using the + icon, you can select multiple groups using AND/OR logic. You can exclude groups using the Exceptions tab. Include at least one group before excluding any groups.

Application copying the file

Select the application or browser.

Note

Browsers are supported only for Microsoft Windows.

Copy Direction

Select either or both directions.

Removable Media

Select one or both options.

Note

CD and DVD devices are supported only for Microsoft Windows.

Exceptions tab

Note

The Exceptions tab is optional.

Actions

Adds or deletes a rule exception.

Name

Enter a unique name for the exception. This field is required.

Description

Optional descriptive text.

State

Select Enabled or Disabled from the drop-down list. The exception state is independent from the rule state.

Classification

Select a classification. See above for option details. The exception classification is independent from the rule classification.

Using classification grouping — When you include multiple classifications in a rule, you can group classifications and create a custom expression to optimize a condition using the Boolean AND or OR operations. When more than two rows of conditions are included, a toggle button appears. Click the toggle button to enable custom classification grouping and type the custom classification grouping expression. For example, if classifications 1, 2, and 3 are included in a Classification condition, you can build an expression similar to ((1 AND 2) OR (1 AND 3)).

The expressions are simplified using the Boolean logic. The brackets are added automatically to the expression if not included. If an expression has both AND and OR, the classification item numbers with AND logic are grouped first and then the classification item numbers with OR logic are grouped. The AND operation takes precedence over the OR operation and the expression is computed from left to right. A classification grouping expression must include all classification item numbers.

End-User

Select a user group from the drop-down list. See above for option details. The exception end-user is independent from the rule end-user.

Application copying the file

Select an application. The exception application is independent from the rule application.

Copy Direction

Select a copy direction. The exception copy direction is independent from the rule copy direction.

Reaction tab

Trellix DLP Endpoint

Data protection and device protection rules have a granular Action definition. You can define different actions for the following:

  • Computer connected to corporate network

  • Computer disconnected from the corporate network

Action

Select an action from the drop-down list. The default is No Action.

Note

Selecting No Action with Report Incident is sometimes referred to as Monitor.

For a list of prevent actions for different types of rules, see the available reactions table.

Note

Encrypt action is not supported on Trellix DLP Endpoint for Mac

When Block option is selected, the file is quarantined and moved to a location that is not accessible to an user. Also, if Store original file as evidence option is not selected in the Reaction tab, then the original file will remain in the local client in a quarantine location for the number of days specified in the Windows Client Configuration page

Note

If you do not set a user notification, you will not be notified if a file is moved to an another location.

User Notification

User notification definitions are stored in the DLP Policy in the Policy Catalog. Select a predefined definition, or click New Item to create one.

Report Incident

Select the checkbox for the rule to trigger a DLP incident.

Store Original File

Select to store the original file as evidence. If the hit highlighting option is enabled for the evidence server, the trigger text is highlighted and stored as a separate file.