Creating a DLP Rule and Associating with an Event

Creating a DLP Rule and Associating with an Event

  1. Go to Policy > Data Loss Prevention.
  2. Add a rule.
    1. Select a rule.
    2. Click Clone and click Clone Above or Clone Below.

      ../../Images/Images-for-HEP-AG/DLP_Clone.png

      Note:

      If you have selected the default rule, select Clone Above.

      The Clone Rule window appears.

      ../../Images/Images-for-HEP-AG/Clone_DLPRule.png

    3. In the Name field, enter a rule name.
    4. From the Applied to list, select a device(s) to which you want to apply the rule.
    5. Click OK.
  3. Select a rule.
  4. Click Clone and click Clone Above or Clone Below.

    ../../Images/Images-for-HEP-AG/DLP_Clone.png

    Note:

    If you have selected the default rule, select Clone Above.

    The Clone Rule window appears.

    ../../Images/Images-for-HEP-AG/Clone_DLPRule.png

  5. In the Name field, enter a rule name.
  6. From the Applied to list, select a device(s) to which you want to apply the rule.
  7. Click OK.
  8. To enable the Gen AI protection, see Enabling GenAI Protect.
  9. Click one of these tabs.

    Outbound events - Outbound data refers to transferring content to external resources.

    Examples:

    • Uploading file to a file sharing website.

    • Entering text in a text box of an external resource, such as ChatGPT.

    • Pasting text in a text box of an external resource, such as ChatGPT.

    Note:

    Enforcement of DLP for Paste and Text Control events is only supported for Generative AI sites.

    Inbound events - Inbound data refers to downloading data and sharing content within internal corporate resources.

    Example - Downloading file from a file sharing website.

    ../../Images/Images-for-HEP-AG/DLPEvents.png

  10. Outbound events - Outbound data refers to transferring content to external resources.

    Examples:

    • Uploading file to a file sharing website.

    • Entering text in a text box of an external resource, such as ChatGPT.

    • Pasting text in a text box of an external resource, such as ChatGPT.

    Note:

    Enforcement of DLP for Paste and Text Control events is only supported for Generative AI sites.

  11. Uploading file to a file sharing website.
  12. Entering text in a text box of an external resource, such as ChatGPT.
  13. Pasting text in a text box of an external resource, such as ChatGPT.
  14. Inbound events - Inbound data refers to downloading data and sharing content within internal corporate resources.

    Example - Downloading file from a file sharing website.

  15. Click Add.

    The Data Protection - New Event window appears.

    DataProtection-ewEvent.png

  16. By default, the event is enabled. To disable, turn off the Status toggle button.
  17. From the Event type list, select one of these.
    Event TypeApplies toDescription
    File upload Outbound events To apply the DLP rule when you upload a file to an external resource.
    Text control Outbound events To apply the DLP rule when you type text in an external resource text box.
    Paste Outbound events To apply the DLP rule when you paste content into an external resource.
    File download Inbound events To apply the DLP rule when you download a file from an internal resource.
    Copy Inbound events To apply the DLP rule when you copy content from an internal resource.
    Note:

    Enforcement of DLP for Paste and Text Control events is only supported for Generative AI sites.

  18. File upload - To apply the DLP rule when you upload a file to an external resource.
  19. From the Destination type list, select one of these.
    Destination typeApplies toDescription
    All File upload N/A
    Url

    File upload

    File download

    Copy

    In the URL field, enter the web addresses.
    Application

    Text control

    Paste

    In the Applications field, select the application(s).
    Domain

    File upload

    File download

    Copy

    In the Domain field, enter the domain.
    Category

    File upload

    Text control

    Paste

    From the Categories & sub categories list, select categories.
    Note:
    • In Inbound events, you can only choose a URL or Domain.

    • In Inbound events, if a source is added for DLP scanning, files downloaded from that source are not scanned by Threat Emulation.

  20. From the Action list, select one of these.
    • Detect - Performs the DLP scan but does not block the data.

    • Prevent - Performs the scan and prevents data transfer.

    • Allow - Allows data transfer.

    • Block - Blocks data without scanning.

    • Ask - Asks user for justification.

    • Redact - Removes sensitive data.

      • Force redact - Automatically replaces sensitive data with asterisk.

  21. Detect - Performs the scan but does not block the data.
  22. Prevent - Performs the scan and prevents data transfer.
  23. Allow - Allows data transfer in certain events.
  24. Block - Blocks the data.
  25. Ask - Asks the user for justification before allowing data transfer.
  26. Redact - Performs a scan and removes sensitive data.
    • Force redact - Automatically replaces sensitive data with asterisk.

  27. Force redact - Automatically replaces sensitive data with asterisk.
  28. To associate data types with an event, click the add icon and select the data type or group.
    Note:

    This step applies only if the Action is Ask, Detect, or Prevent.

  29. Click Save.

    The events are displayed in the Outbound events and Inbound events columns.

    OutboundInboundColumn.png

  30. To delete an event, select it and click Delete.
  31. To edit an event, select it, click Edit, make changes, and click OK.
  32. To disable all events, turn off the Disable all toggle button.

    InboundDisable.png

  33. Click Save & Install.

    The Install Policy window appears.

    ../../Images/Images-for-HEB-AG/Harmony%20Browse_InstallPolicy.png

  34. Click Install.