Allow people in the human resources user group to send messages that contain personal credit information by obtaining information from your Active Directory.
Register an Active Directory server with ePO - On-prem. Use the Registered Servers features in ePO - On-prem to add details of the server.
Follow these high-level steps to:
(Optional for Trellix DLP Network Prevent only) Select an LDAP server to get the user group from.
Create a personal credit information classification.
Create a rule set and a rule that acts on the new classification.
Make the human resources user group exempt from the rule.
Block messages that contain personal credit information.
Apply the policy.
Tip
To ensure that your rules identify potential data loss incidents with minimal false positive results, create your rules using the No action setting. Monitor the DLP Incident Manager. until you are satisfied that the rule identifies incidents correctly, then change the Action to Block.
For details about product features, usage, and best practices, click ? or Help.
Select the LDAP server that you want to get the user group from.
In ePO - On-prem, open the Policy Catalog.
Select the Trellix DLP Network Prevent Server policy.
Open the Users and Groups category and open the policy that you want to edit.
Select the Active Directory servers that you want to use.
Click Save.
From the ePO - On-prem menu, select Classification, and create a duplicate PCI classification.
Create the rule set and exceptions to it.
Open the DLP Policy Manager.
In Rule Sets, create a rule set called
Block PCI for DLP Network Prevent and Endpoint.Open the rule set you created, select Action → New Rule → Email Protection, and type a name for the rule.
In Enforce On select DLP Endpoint for Windows and DLP Network Prevent.
In Classification of, select the classification you created.
Leave Sender, Email Envelope, and Recipient with the default settings.
Specify the user group that you want to exclude from the rule.
Select Exceptions, click Actions → Add Rule Exception, and name it
Human resource group exception.Set the State to Enabled.
In Classification of, select contains any data (ALL).
In Sender select Belongs to one of end-user groups (OR).
Select New Item, and create an end-user group called
HR.Click Add Groups, select the group, and click OK.
Set the action you want to take if the rule triggers.
Select the group you created and click OK.
Select the Reaction tab.
In the DLP Endpoint section, set the Action to Block.
If DLP Endpoint is selected, you must set a reaction.
In the DLP Network Prevent section, set the X-RCIS-Action header value to Block. You can also configure to include custom headers in the email message. Using the custom header definitions you have created and the built-in custom header definitions, you can configure the custom header to report the number of rules and cumulative score of the rules that violated a policy.
Note
If you want to test the rule, you can keep the Action as No Action until you are satisfied that it triggers as expected.
Select Report Incident.
Save the rule and click Close.
Apply the rule.
In the DLP Policy Manager, select Policy Assignment.
Note
Pending Changes, shows Yes.
Select Actions → Assign Rule Sets to a policy.
Select the rule set you created.
Select Actions → Apply Selected Policies.
Click Apply policy.
Pending Changes shows No.