Configuring the Write Action

The Write action lets users:

  • Create new files

  • Copy or move files to devices

  • Delete files from devices

  • Change file contents on devices

  • Change file names on devices

The default predefined write actions are:

  • Data Type - Encrypt business-related data on storage devices - All Files that are defined as business-related data must be written to the encrypted storage. Non-business related data can be saved to the device without encryption. See Configuring Business-Related File Types.

  • Allow writing data on storage devices:

    • Allow encryption - Users can write only encrypted files to storage devices.

    • Enable deletion of file on read-only media - Allow users to delete files on devices with read-only permissions.

You can configure these settings for specific devices.

To configure the Write action:

  1. In the Media Encryption tab, go to Exclusions Center.

  2. Click New to create a new exclusion or configure an existing exclusion on the list.

  3. Per each device, configure the options as necessary for: Data Type and Write Encrypted:

    • Data Type - Select one of these options:

      • Allow any data - Users can write all file types to storage devices.

      • Encrypt business-related data - Users must encrypt all business-related files written to storage devices. Other files can be written without encryption. See Configuring Business-Related File Types.

      • Encrypt all data - Users must encrypt all files written to storage devices.

      • Block any data - Users cannot write any files to storage devices.

Notes:

  • If no read policy is allows, the write policy is disabled automatically.

  • If Block any Data is selected, Allow encryption and Configure File Types are disabled.

Configuring Business-Related File Types

The organization's policy defines access to business and non-business related data. Business-related files are confidential data file types that are usually encrypted in the business-related drive section of storage devices. These files are defined as business-related file types by default:

  • Multimedia - QuickTime, MP3, and more.

  • Executable - Exe, shared library and more.

  • Image - JPEG, GIF, TIF and more.

These files are defined as non-business related file types by default:

  • Spreadsheet - Spreadsheet files, such as Microsoft Excel.

  • Presentation - Presentation files, such as Microsoft Power Point.

  • Email - Email files and databases, such as Microsoft Outlook and MSG files.

  • Word - Word processor files, such as Microsoft Word.

  • Database - Database files, such as Microsoft Access or SQL files.

  • Markup - Markup language source files, such as HTML or XML.

  • Drawing - Drawing or illustration software files, such as AutoCAD or Visio.

  • Graphic - Graphic software files such as Photoshop or Adobe Illustrator.

  • Viewer - Platform independent readable files, such as PDF or Postscript.

  • Archive - Compressed archive files, such as ZIP or SIT.

To see the list of business-related file types and non-business related file types:

In the Endpoint Web Management Console, go to the Policy view > Data Protection > Capabilities and Exclusions pane > Media Encryption > Write Policy > Configure File Types > View Mode. Select Non-Business-Related or Business-Related to see the relevant file types.

To configure business and non-business related file types:

  1. In the Endpoint Web Management Console, go to the Policy view > Data Protection > Capabilities and Exclusions pane > Media Encryption > Write Policy > Configure File Types.
  2. You can:

    • Add or delete files from the business-related or non-business related file list. In View Mode, select Business-related or Non-business related. Add or delete the required files. A file type which is not in the business-related file list, is automatically included in the non business-related file type list.

    • Create new file types in the business-related or non-business related file type list. Click the Create new file type button. The File type add/edit window opens. Configure Name, File Extension and File Signatures and click OK.