Use case: Allow a specified user group to send credit information

Prev Next

Allow people in the human resources user group to send messages that contain personal credit information by obtaining information from your Active Directory.

Register an Active Directory server with ePO - SaaS. Use the Registered Servers features in ePO - SaaS to add details of the server.

Follow these high-level steps:

  1. (Optional for Trellix DLP Network Prevent – SaaS only) Select an LDAP server to get the user group from.

  2. Create a personal credit information classification.

  3. Create a rule set and a rule that acts on the new classification.

  4. Make the human resources user group exempt from the rule.

  5. Block messages that contain personal credit information.

  6. Apply the policy.

Tip

To ensure that your rules identify potential data loss incidents with minimal false positive results, create your rules using the No action setting. Monitor the Protection Workspace. until you are satisfied that the rule identifies incidents correctly, then change the Action to Block.

  1. Select the LDAP server that you want to get the user group from.

    1. In ePO - SaaS, open the Policy Catalog.

    2. Select the Trellix DLP Network Prevent Server policy.

    3. Open the Users and Groups category and open the policy that you want to edit.

    4. Select the Active Directory servers that you want to use.

    5. Click Save.

  2. From the ePO - SaaS menu, select Classification, and create a duplicate PCI classification.

  3. Create the rule set and exceptions to it.

    1. Open the DLP Policy Manager.

    2. In Rule Sets, create a rule set called Block PCI for DLP Network Prevent and Endpoint.

    3. Open the rule set you created, select ActionNew RuleEmail Protection, and type a name for the rule.

    4. In Enforce On select DLP Endpoint for Windows and DLP Network Prevent.

    5. In Classification of, select the classification you created.

    6. Leave Sender, Email Envelope, and Recipient with the default settings.

  4. Specify the user group that you want to exclude from the rule.

    1. Select Exceptions, click ActionsAdd Rule Exception, and name it Human resource group exception.

    2. Set the State to Enabled.

    3. In Classification of, select contains any data (ALL).

    4. In Sender select Belongs to one of end-user groups (OR).

    5. Select New Item, and create an end-user group called HR.

    6. Click Add Groups, select the group, and click OK.

  5. Set the action you want to take if the rule triggers.

    1. Select the group you created and click OK.

    2. Select the Reaction tab.

    3. In the DLP Endpoint section, set the Action to Block.

      If DLP Endpoint is selected, you must set a reaction.

    4. In the DLP Network Prevent section, set the X-RCIS-Action header value to Block. You can also configure to include custom headers in the email message. Using the custom header definitions you have created and the built-in custom header definitions, you can configure the custom header to report the number of rules and cumulative score of the rules that violated a policy.

      Note

      If you want to test the rule, you can keep the Action as No Action until you are satisfied that it triggers as expected.

    5. Select Report Incident.

    6. Save the rule and click Close.

  6. Apply the rule.

    1. In the DLP Policy Manager, select Policy Assignment.

      Note

      Pending Changes, shows Yes.

    2. Select ActionsAssign Rule Sets to a policy.

    3. Select the rule set you created.

    4. Select ActionsApply Selected Policies.

    5. Click Apply policy.

      Pending Changes shows No.