Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Forcepoint DLP Release Notes v8.6 : New in Forcepoint DLP
New in Forcepoint DLP
Release Notes | Forcepoint DLP | v8.6.0 | 30-November-2018
DLP Cloud Applications data discovery
The Forcepoint DLP Cloud Applications license now enables data discovery and remediation of sensitive data at rest that is stored in sanctioned cloud applications. Supported cloud applications include Office 365, Box, G-Suite, Salesforce, and ServiceNow, with additional cloud applications added regularly.
DLP Cloud Applications provides complete visibility and API-based remediation controls over uploads, downloads, sharing activities, and data at rest across sanctioned cloud applications.
Existing data discovery policies and classifiers (including fingerprint and machine learning classifiers) can be extended to sanctioned cloud applications. A range of remediation actions is available, including removing sharing permissions and file quarantine (actions vary between cloud applications).
DLP Cloud Applications leverages Forcepoint CASB to apply DLP policies via a Forcepoint hosted service, ensuring that data is scanned and remediated in the cloud. Incidents and forensics are stored securely within your existing Forcepoint DLP infrastructure.
See Forcepoint DLP Administrator Help for more information about cloud discovery scans. See Configuring the CASB service in the Forcepoint DLP Administrator Help for information about configuring the Forcepoint CASB service.
Data labeling framework
Version 8.6 of Forcepoint DLP introduces a new data labeling framework with support for Microsoft Information Protection, Boldon James Classifier, and Titus labeling solutions.
Customers using Microsoft Information Protection (E3 license or higher) can import classification labels directly from the Microsoft Azure Portal into Forcepoint Security Manager and allocate labels to the new File Labeling classifier. This enables labels to be detected within DLP policy rules with a high degree of accuracy. Use of this feature requires authentication with Microsoft Office 365 administrator credentials; it is recommended to use the credentials of an administrator who has visibility over all Microsoft Information Protection labels used in the organization. The ability to apply labels and protection templates as policy actions is planned for future releases.
Forcepoint DLP Endpoint (Windows) supports automated decryption of files protected using Microsoft Rights Management to enable DLP policies to be applied to RMS protected content.
Customers using Boldon James Classifier can import classification labels created using Classifier into Forcepoint Security Manager and allocate labels to the new File Labeling classifier. This enables labels to be detected within DLP policy rules with a high degree of accuracy. It is also possible to automatically apply Boldon James Classifier labels via DLP policy actions plans for data at rest on DLP Endpoint (Windows). Additional automated labeling actions for network discovery can be configured using remediation scripts.
*
See Configuring File Labeling in the Forcepoint DLP Administrator Help for more information.
OCR enhancements
Forcepoint DLP now provides a Trade Agreements Act (TAA) certified Optical Character Recognition (OCR) module. U.S. Government customers are subject to the TAA, meaning all products listed on the GSA Schedule Contract must be manufactured or "substantially transformed" in the United States or a TAA "designated country;" https://www.acquisition.gov/sites/default/files/current/far/html/52_223_226.html#wp1169151
The OCR engine also adds support for Arabic and Thai languages, and supports OCR for images embedded within Microsoft Office documents and PDFs.
*
Forcepoint One Endpoint introduction
In this release, Forcepoint One Endpoint replaces the legacy Endpoint DLP agent for Windows and macOS. During 2019, additional Forcepoint products will migrate to Forcepoint One Endpoint, providing a single unified endpoint agent for all Forcepoint security products.
In Forcepoint DLP version 8.6.0, the endpoint package builder combines Forcepoint One Endpoint for DLP (and Dynamic Data Protection) with the existing Web Direct Connect Endpoint (DCEP) and Proxy Connect Endpoint (PCEP) endpoint agents into a single package for deployment to managed endpoints. The endpoint upgrade process is the same as in previous DLP releases.
The endpoint package builder is no longer included in the Forcepoint Security Manager installer and must be downloaded from the Forcepoint One Endpoint dedicated download section on www.forcepoint.com.
Endpoint: Enhanced monitoring of browser file uploads
Version 8.6 adds a new feature that enhances the detection of sensitive data being uploaded to specified cloud applications through supported web browsers. Incidents can be generated and activities that put sensitive data at risk can be audited or blocked. This feature is supported on both Windows and Mac endpoints, and can be accessed from the detection tab on the Settings > General > Endpoint page.
See Forcepoint DLP Administrator Help for more information about this feature.
Endpoint: Browser extension mode configuration
In version 8.6, you can specify the mode in which Forcepoint Endpoint browser extensions operate for the Google Chrome browser.
On the Settings > Deployment > Endpoint > Endpoint Profile page Properties tab, select a mode for the Chrome extension:
*
*
*
See Endpoint profile: Properties tab for information about endpoint properties.
Endpoint: Enhanced employee coaching details
Security administrators can now decide to display additional incident detail in employee confirmation dialog boxes and the Endpoint Log Viewer. This information is designed to enable an end user to make a more informed decision about how they handle sensitive business data. This option is set in the Settings > Deployment > Endpoint > Endpoint Profiles page Properties tab, under Interactive Mode Options.
Forcepoint DLP Email Gateway and Forcepoint Security Manager deployment via Azure Marketplace
Forcepoint DLP Network and Forcepoint DLP Suite licenses include Forcepoint DLP Email Gateway, an enterprise-grade email Mail Transport Agent (MTA) option for network email DLP policy enforcement.
Forcepoint DLP Email Gateway can be deployed on-premises as a virtual appliance or in a public cloud environment through the Microsoft Azure Marketplace. This version adds support to deploy Forcepoint Security Manager in Azure alongside Forcepoint DLP Email Gateway, allowing your full email protection solution to reside within the Azure cloud environment. This solution will be available in the Azure Marketplace in early 2019.
The steps for installing DLP Email Gateway and Security Manager in Azure are the same as those for Forcepoint Email Security. After installation, enter your subscription key in the Security Manager to enable the options for Forcepoint DLP Email Gateway.
Refer to Forcepoint Email Security and Forcepoint DLP Email Gateway documentation for more information:
*
*
*
Support for installation on Red Hat 7.x
Starting with version 8.6.0, the Forcepoint DLP Analytics Engine and Protector software packages can be installed on a Red Hat 7.x operating system. See Forcepoint DLP Installation Guide for information about installing the Analytics Engine and the Protector.
Fresh banner design
The Forcepoint Security Manager banner has been slightly redesigned to provide a streamlined experience. A pull-down menu is now used to access installed product modules, as shown in the following image:
To access the Data Security module, use the following steps:
1.
A pull-down menu displays the available modules.
2.
Click Data.
The Data Security module displays.
New and enhanced policies, rules, and classifiers
New policies, rules, classifiers and file types were added in this release, including:
*
*
*
*
*
*
*
*
*
New
New Latin American policies, rules, and classifiers
*
*
*
*
*
*
New Private Keys policy, rules, and classifiers
*
New "Controlled Unclassified Information (CUI)" policy, rules, and classifiers
*
New policies, rules, and classifier for Digitally Signed PDF Files
*
New policy "Risk Management Framework (RMF) for Department of Defense Information Technology (IT)"
*
New APAC discovery policies
*
New passport rules and classifiers
*
*
*
New rules and classifiers for Spain
*
New computer-aided design (CAD) rules and classifiers
*
New database rules and classifiers
*
New Encrypted Microsoft OneNote rule and classifier
*
New rules and improved classifiers for South Africa
*
*
New Email Address and Password rules
*
New Credit File (also known as Credit Report) rules
*
New File Types
*
Enhanced
Improved classifiers
*
*
*
*
*
*
*
*
*
*
Renamed policies
*
*
Removed policies and rules
*
*
*
*

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Forcepoint DLP Release Notes v8.6 : New in Forcepoint DLP
Copyright 2018 Forcepoint. All rights reserved.