Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Defining Resources > Remediation > Action Plans > Adding a new action plan
Adding a new action plan
Administrator Help | Forcepoint DLP | Version 8.4.x
Use the Policy Management > Resources > Action Plans > Action Plan Details page to create or edit an action plan.
To access this page, click New in the toolbar at the top of the content pane on the Action Plans page.
To create an action plan:
1.
Enter a Name and Description for the action plan.
2.
*
*
*
Standard Forcepoint DLP options
On the Data Loss Prevention tab, complete the fields as follows. See Possible actions for an action plan for a description of each possible action.
1.
 
2.
 
3.
For Cloud Channels, use the File sync and sharing drop-down list to select an action to take when a breach is discovered during file sync or sharing with a cloud service, such as OneDrive for Business or Box.
*
Select Permit to allow files to be synchronized or shared.
*
Select Delete file to permanently erase the file that users are trying to sync or share. When a file is deleted, it cannot be recovered.
4.
By default, all incidents are audited. Clear the Audit incident check box if you do not want to audit incidents.
 
Warning 
When Audit incident is select, also select one or more of the following options:
*
Select Include forensics to include information about the transaction that resulted in the incident, such as the contents of an email body: From:, To:, Cc: fields; attachments, URL category, hostname, file name, and more.
Forensics display in the incident report.
*
Select Run remediation script to have the system run a script when an incident is discovered, then select the script to use from the drop-down list. See Remediation scripts for more information.
*
Select Run endpoint remediation script to have the system run an endpoint remediation script when an incident is discovered, then select the script to use from the drop-down list.
*
Select Send syslog message to notify an outside syslog server or ticketing system of the incident.
*
Select Send email notifications to send an email message to a designated recipient when a policy is breached.
*
*
*
Click New to create a custom message.
See Notifications and Adding a new message for details.
 
Tip 
5.
*
To have the system run a remediation script when an incident is discovered, select Run remediation script, then select a script from the drop-down list. See Remediation scripts.
*
To have the system run an endpoint remediation script when an incident is discovered, select Run endpoint remediation script, then select a script from the drop-down list.
6.
Click OK to save your changes.
Forcepoint Web Security mode
1.
*
Permit or allow the HTTP, HTTPS, or FTP request to go through.
*
Block or deny the request.
2.
Select Audit incident to have Forcepoint DLP to log incidents. When logging is enabled, email notifications are also available.
3.
Select Send email notifications to send an email message to a designated recipient when a policy is breached.
*
*
*
Click New to create a custom message.
See Notifications and Adding a new message for details.
 
Tip 
 
4.
Click OK to save your changes.
Forcepoint Email Security mode
1.
With Forcepoint Email Security (on-premises), the action option configured here applies to all email directions.
For cloud infrastructure deployments such as Microsoft Azure, this option applies only to outbound email. (Inbound and Internal email is permitted, and an alert is sent to the Forcepoint Email Security administrator.)
*
Permit the message to go through.
*
Block or deny the message or post.
*
Quarantine the message.
Select Encrypt on release to have the system encrypt the message before it's released.
*
Drop attachments that are in breach of policy. Quarantines email messages that:
*
*
*
*
 
Note 
Select Encrypt on release to have quarantined messages encrypted before they're released. If an attachment has been dropped, this option reattaches it and encrypts both the body and attachment before releasing the message.
(Incidents are released when an administrator selects Remediate > Release on the incident details toolbar.)
*
Encrypt the message.
 
Tip 
2.
Select Audit incident to have Forcepoint DLP to log incidents in the incident database. By default, audit is selected irrespective of the action.
 
Warning 
When Audit incident is enabled, several additional actions are available. Select any of these actions to apply.
3.
If you select Send email notifications:
*
*
*
Click New to create a custom message.
See Notifications and Adding a new message for details.
 
Tip 
4.
Click OK to save your changes.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Defining Resources > Remediation > Action Plans > Adding a new action plan
Copyright 2017 Forcepoint. All rights reserved.