![]() |
![]() |
![]() |
![]() |
Creating Discovery Policies > Creating a discovery policy
|
1.
|
Click Add in the toolbar at the top of the content pane, then select either Predefined Policy or Custom Policy.
|
1.
|
Click Next and select the geographical regions to cover.
|
2.
|
Click Next and select the industries to cover.
|
3.
|
The Finish screen appears, summarizing your selections. Click Finish. The Forcepoint DLP policy database is updated and a confirmation message appears. The policies you selected appear in a list.
|
4.
|
1.
|
2.
|
Mark Enabled to activate the policy.
|
3.
|
a.
|
Select the type of accounts to Display (Administrators, by default).
|
c.
|
Click OK.
|
4.
|
Indicate whether to Use the policy name for the rule name (default) or Use a custom name for the rule.
|
5.
|
Click Next.
|
6.
|
Use the Condition tab, specify whether this rule monitors specific data or all activities, and whether the data is monitored in all parts of the transaction as a whole or each part of the transaction separately.
|
7.
|
Click Add to add one of the following content classifiers or attributes to the condition you are creating:
|
![]() |
Patterns & phrases: Follow the Select a Content Classifier wizard and choose one from the list of existing classifiers or build your own. Toggle between the General and Properties tabs to complete the information and click OK. See Patterns & Phrases for details.
|
![]() |
File Properties: Select file properties to add to this policy. Click OK. See File properties for details.
|
![]() |
Fingerprint: Select the fingerprint classifier to use for this policy. Click OK. See Fingerprint for details.
|
8.
|
Select an answer for the question: When do you want to trigger the rule?
|
9.
|
Click Next to define the Severity & Action for incidents that match this rule and to specify the action plan to be taken. Click Advanced to further specify the severity according to the number of matched conditions.
|
10.
|
Click Next to complete the wizard.
|
11.
|
Click Finish to create the new rule and add it to the policy.
|
![]() |
![]() |
![]() |
![]() |
Creating Discovery Policies > Creating a discovery policy
|