Creating Discovery Policieshttp://www.websense.com/content/support/library/data/v76/help/discovery.aspx

TRITON - Data Security Help

Creating Discovery Policies

Note: This chapter applies only to customers with Websense Data Discover. It does not apply to those with Websense Web Security Gateway Anywhere.

Discovery is the act of determining where sensitive content is located in your enterprise. A discovery policy might say, for instance: every Sunday, scan all the computers in the network looking for financial documents containing the keyword “Confidential”. Log what is discovered and send a notification to the Finance manager.

If you want to monitor what is done with those financial records or stop them from leaving the building, you need to create a network or endpoint policy.

Discovery enables you to find data at rest on your network and identify the endpoint machines that represent the greatest risk. This allows you to prioritize actions taken on the files and machines.

Performing discovery is comprised of 2 basic steps:

  1. Creating a discovery policy
  2. Scheduling Discovery Tasks

Structurally, discovery policies are the same as data loss prevention policies. Both are comprised of rules, exceptions, content classifiers, and resources. Rather than specifying destination channels to scan such as FTP, SMTP, and printers, however, you create a discovery task that describes where and when to perform the discovery, including specific network and endpoint computers to scan. On networks, this may include a file system, SharePoint directory, database, or Outlook PST file.

Click View Complete Document for more.