1.
|
Click New.
|
3.
|
On the Data Loss Prevention tab, complete the fields as follows. See Possible actions for a description of each possible action.
|
You can Permit the file to be synced or shared, or you can Delete it. When a file is deleted, it cannot be recovered.
|
|||
When Audit incident is enabled, several more options are made available. You can:
|
|||
Select this check box if you want to notify an outside syslog server or ticketing system of the incident.
|
|||
Select this check box to send an email message to a designated recipient when a policy is breached. Select the message or messages to send. Click a link to view or modify standard messages. Click New to create a custom message. See Notifications and Adding a new message for details.
Tip: There is a benefit to using the same template for each action plan. The system gathers notifications for individual users according to templates and combines them into a single notification. So if an incident contains 10 different rules, each with a different action plan but the same template, the user receives a single notification with the details of all the breaches.
|
Quarantine email messages containing sensitive data. Network email can be encrypted before it's released. Select Encrypt on release to enable this feature.
|
|
Select Encrypt on release if you want quarantined messages to be encrypted before they're released. If an attachment has been dropped, this option reattaches it and encrypts both the body and attachment before releasing the message.
To release an incident, an administrator selects Remediate > Release on the incident details toolbar.
|
|
To configure the default action, navigate to Settings > General > Endpoint and select Block or Permit on the General tab.
|
1.
|
Click OK to save your changes.
|
1.
|
Click New.
|
|
|||||
Select this check box to send an email message to a designated recipient when a policy is breached. Select the message or messages to send. Click a link to view or modify standard messages. Click New to create a custom message. See Notifications and Adding a new message for details.
Tip: There is a benefit to using the same template for each action plan. The system gathers notifications for individual users according to templates and combines them into a single notification. So if an incident contains 10 different rules, each with a different action plan but the same template, the user receives a single notification with the details of all the breaches.
|
4.
|
Click OK to save your changes.
|
1.
|
Click New.
|
Select Encrypt on release if you want quarantined messages to be encrypted before they're released. If an attachment has been dropped, this option reattaches it and encrypts both the body and attachment before releasing the message.
To release an incident, an administrator selects Remediate > Release on the incident details toolbar.
To create an action in the Email Security manager, select Policy Management > Actions, click Add, then indicate that the action is to be used by DLP policies only.
|
|||||||||||
When Audit incident is enabled, several more options are made available. You can:
|
|||||||||||
Select this check box to send an email message to a designated recipient when a policy is breached. Select the message or messages to send. Click a link to view or modify standard messages. Click New to create a custom message. See Notifications and Adding a new message for details.
Tip: There is a benefit to using the same template for each action plan. The system gathers notifications for individual users according to templates and combines them into a single notification. So if an incident contains 10 different rules, each with a different action plan but the same template, the user receives a single notification with the details of all the breaches.
|
4.
|
Click OK to save your changes.
|