27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OL-25136-01<br />

Data Loss Prevention<br />

CHAPTER<br />

11<br />

In the Information Age, your organization’s data is one of its most prized possessions. Your organization<br />

spends a lot of money making data available to your employees, customers, and partners over email and<br />

the Web. This increased access poses challenges for information security professionals to figure out how<br />

to prevent the malicious or unintentional distribution of sensitive and proprietary information over the<br />

Internet.<br />

Cisco provides the following methods to protect your organization’s information and intellectual<br />

property and enforce compliancy with state and federal regulations using the Email Security appliance:<br />

RSA Email DLP. A solution local to the Email Security appliance that includes an integrated data<br />

loss prevention (DLP) scanning engine and DLP policy templates designed by RSA Security Inc. to<br />

identify and protect sensitive data.<br />

RSA Enterprise Manager. Users of RSA’s Enterprise Manager can partner their Email Security<br />

appliances with the Enterprise Manager software and use RSA’s DLP technologies to scan outgoing<br />

message. Whereas RSA Email DLP is local to an individual Email Security appliance, RSA<br />

Enterprise Manager allows you to manage multiple Email Security appliances on the same network<br />

from a centralized interface. Users of RSA’s DLP Datacenter can use its fingerprinting detection<br />

method for scanning source code and documents in certain DLP policies. Enterprise Manager is a<br />

third-party software from RSA and cannot be purchased from Cisco.<br />

Note This chapter describes how to configure the settings on the Email Security appliance to connect it to<br />

Enterprise Manager and provides an overview of how the appliance works as an Enterprise Manager<br />

partner device. For information on configuring the Enterprise Manager and its DLP policies, see RSA’s<br />

documentation for Enterprise Manager, including the online help and the technical note Managing<br />

Partner Device DLP with Enterprise Manager.<br />

Data Loss Prevention Overview, page 11-2<br />

Data Loss Prevention Global Settings, page 11-2<br />

Message Actions, page 11-5<br />

RSA Email DLP, page 11-8<br />

DLP Policies, page 11-10<br />

RSA Enterprise Manager, page 11-27<br />

Configuring Per-Recipient Policies for DLP, page 11-31<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

11-1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!