You can define protection rules when changing or creating a protection policy or rule group.
Task
- Select Menu → Policy → Policy Catalog.
-
Select
Solidcore 8.x.x: Change Control for the product.
You can create a policy or duplicate an existing one.
-
Read-protect files and directories.
- Select a policy from the list, then click Add on the Read-Protect tab. The Add File dialog box appears.
- Specify the file or directory name and indicate whether to include or exclude from read protection.
- Click OK.
-
Write-protect files and directories.
- Select a policy from the list, then click Add on the Write-Protect File tab. The Add File dialog box appears.
- Specify the file or directory name and indicate whether to include or exclude from write protection.
- Click OK.
-
Specify trusted programs permitted to override the read and write protection rules.
- Click Add on the Updater Processes tab. The Add Updater dialog box appears.
- Enter the location of the file.
- Enter a unique identification label for the executable file.
-
Specify conditions that the file must meet to run as an updater:
- Select None to allow the file to run as an updater without any conditions.
- Select Parent to allow the file to run as an updater only if it is started by the specified parent.
- Indicate whether to disable inheritance for the updater. For example, if Process A (that is set as an updater) starts Process B, disabling inheritance for Process A makes sure that Process B doesn't become an updater.
- Indicate whether to suppress events generated for the actions performed by the updater. Typically, when an updater changes a protected file, a File Modified event is generated for the file. If you select this option, no events are generated for changes made by the updater.
- Click OK.