27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Data Loss Prevention Overview<br />

11-2<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

Chapter 11 Data Loss Prevention<br />

The Cisco <strong>IronPort</strong> Email Security appliance’s Data Loss Prevention feature secures your organization’s<br />

information and intellectual property and enforces regulatory and organizational compliance by<br />

preventing users from emailing sensitive data from your network. You define what kind of data your<br />

employees are not allowed to email by creating DLP policies that scan outgoing messages for any data<br />

that may violate laws or corporate policies.<br />

This document refers to any message content that violates your DLP policies as DLP violation and the<br />

occurrence of message containing a violation as a DLP incident. When a DLP incident occurs, the<br />

appliance takes the appropriate actions with the message to secure the information, such as quarantining<br />

the message and sending a notification to someone in your organization responsible for data security.<br />

The Email Security appliance has an integrated DLP scanning engine and a set of DLP policies created<br />

by RSA, which is referred to collectively in this documentation and on the appliance as RSA Email DLP.<br />

You can configure the Email Security appliance’s outgoing mail policies to scan messages and<br />

attachments for DLP violations. RSA Email DLP includes over 100 DLP policy templates designed by<br />

RSA. See RSA Email DLP, page 11-8 for more information.<br />

For users of RSA’s Enterprise Manager, you can connect your Email Security appliances to Enterprise<br />

Manager as partner devices, allowing the appliances to use Enterprise Manager as a centralized<br />

management interface for multiple appliance on the network. Enterprise Manager provides a wider array<br />

of DLP technologies than RSA Email DLP does on the local Email Security appliance.<br />

RSA Email DLP’s policies are configured locally on the appliance while Enterprise Manager can<br />

manage the DLP policies for multiple Email Security appliances, including clustered appliances, and<br />

pushes those policies to the appliances for when the outgoing mail policies perform DLP scans.<br />

If enabled, DLP scanning is performed in the appliance’s “work queue” for outgoing mail immediately<br />

after the Outbreak Filters stage. See Message Splintering, page 6-4 for more information.<br />

Data Loss Prevention Global Settings<br />

To scan outgoing emails for sensitive data, you must first enable the Data Loss Prevention feature using<br />

the Security Services > RSA Email DLP page. You can choose whether to use RSA Enterprise Manager<br />

or RSA Email DLP for data loss prevention.<br />

Select RSA Email DLP if you want to configure and manage your DLP policies on the local Email<br />

Security appliance. You can choose to either run the DLP Assessment Wizard to enable the most popular<br />

DLP policies on the appliance or manually configure DLP policies. To learn how to run the DLP<br />

Assessment Wizard, see Using the DLP Assessment Wizard, page 11-17. To learn how to manually<br />

configure DLP policies, see DLP Policy Manager, page 11-11.<br />

After you enable RSA Email DLP, you can enable the policies on your outgoing mail policies using the<br />

Email Security Manager. For more information, see Configuring Per-Recipient Policies for DLP,<br />

page 11-31.<br />

Select RSA Enterprise Manager if you want to use Enterprise Manager to configure and manage the DLP<br />

policies for your appliances. Enterprise Manager receives outgoing mail policy and message action<br />

definitions from the Email Security appliance and then pushes DLP policies to connected Email Security<br />

appliances. Administrators can also view DLP incidents and send commands to delete or release<br />

messages from quarantines using Enterprise Manager.<br />

OL-25136-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!