This section describes all step-by-step tasks that you need to perform to create and apply a policy to block email attachments with sensitive data. Trellix DLP Network Prevent can use file extension or true file type in classification criteria to block email attachments with sensitive data. You can also use these classifications to block attachments sent in web posts or network.
Consider that you have some architecture and planning diagrams of your business solution in Autocad and Visio formats, which you have saved in a shared location. The administrator wants to block all Autocad or Visio attachments with sensitive data from going outside the network. You can use these steps to block attachments for these specific extensions and prevent any data loss.
Create a definition or choose a built-in definition. (See Step 1 in the following task)
Create a classification and classification criteria. (See Step 2 in the following task)
Create a rule set and rules. (See Step 3 in the following task)
Assign rule sets to policy. (See Step 4 in the following task)
Assign and push policy to system. (See Step 5 in the following task)
Choose a built-in definition or create a definition to include phrases that must be tracked.
In ePO - On-prem, go to Menu → Data Protection → Classification and select Definitions.
Select Dictionary, click Action → New Item, give the dictionary definition a name and an optional description, then click Action → Add. You can also use an existing dictionary.
In Phrase, type the word
internal, then set the Score as1and select Case Sensitive to only match on the keyword when it is lowercase. To add multiple phrases, you can click Save and New..png)
Click Save.
Create a classification and classification criteria. You can also edit an existing classification.
Select Classification.
Click Actions, then click New Classification and type a unique name and an optional description. Select Save Classification in the Actions menu.
In the right pane, click Actions, then select New Content Classification Criteria and type the classification criteria name.
In the Data conditions properties, click to select Dictionary and add the dictionary that you created.
In the File conditions properties, click to select File Extensions and True File Type.
Classification criteria with true file type helps detect attachment violations when file extensions are renamed and sent as attachments. For example, a .cpp file saved as .txt file can be detected using the true file type classification criteria.
For the File Extensions property, click the select icon (
) to open the Choose from existing values window. Choose all file types that you want to block. To add more values, click +.For the True File Type property, click the select icon (
) to open the Choose from existing values window. Choose all file types that you want to block. To add more values, click +.Click Save.
Create a rule set that includes an Email Protection rule and add the classification criteria that you created.
Go to Menu → Data Protection → DLP Policy Manager.
Click Actions → New Rule Set. Enter a name for the rule set and provide a description for your reference. Click OK.
A new rule set is created. Click the rule set and then create a new rule.
Click Actions → New Rule → Email Protection rule.
Type the rule name and optionally enter the description. Select the state as Enabled and click the checkbox to select Trellix Network DLP to enforce the policy on.
In the Conditions tab, in Classification of, select one of the attachments (*) and contains one of (OR), and then select the classification criteria you created.
Set the Recipient to any recipient (ALL).
In the Reactions tab, set the reaction you want to take when the rule gets triggered. Set the Action to Block and return email to sender, then select the appropriate User Notification. Click Save.
Assign rule sets to a policy. Before you assign rule sets to a policy, activate the rule set.
Go to Menu → Policy → Policy Catalog.
In the Product drop down list, select Data Loss Prevention <version> and select DLP Policy.
Click the Edit link of the policy you want to update.
In the policy page, go to Active Rule Sets → Actions, then click Activate Rule Set.
The Activate Rule Set window opens.
Select the checkboxes of one or more rule sets that you want to apply to the policy.
Click OK and click Apply Policy.
Trellix DLP displays the status of the policy applied.
Assign and push the policy to Trellix DLP Network.
Go to Menu → Systems → System Tree.
Select the checkbox of one or more Trellix DLP Network Prevent appliances (target system) that you want to assign the policy to.
Click Wake Up Agents to push the policy to Trellix DLP Network immediately.
The Wake Up Trellix Agent window opens.
Next to Wake-up call type, select whether to send an Agent Wake-Up Call or a SuperAgent Wake-Up Call.
Accept the default Randomization (0–60 minutes) or type a different value.
If you type 0, agents respond immediately.
Click OK to send the wake-up call to the target appliances.
Alternatively, you can use the Break inheritance and assign the policy and settings below option to push the policy. For information, see Assign and push a policy to a system.
The appliance is now set with policy to block email attachments with sensitive data.