27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

11-10<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

Chapter 11 Data Loss Prevention<br />

For more information on content matching classifiers, see Content Matching Classifiers,<br />

page 11-20.<br />

For more information on the DLP Incidents report, see the “Using Email Security Monitor” chapter<br />

in the Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> for Email Daily Management <strong>Guide</strong>.<br />

For information on searching for messages with DLP violations in Message Tracking, see the<br />

“Tracking Email Messages” chapter in the Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> for Email Daily Management<br />

<strong>Guide</strong>.<br />

Note The scanning engine only uses a classifier once when scanning a message. If an outgoing mail policy<br />

has two or more DLP policies that use the same classifier, the policies use the result from a single<br />

classifier scan.<br />

Hardware Requirements<br />

DLP Policies<br />

Content of Policies<br />

The RSA Email DLP feature is supported on all C-Series and X-Series appliances, except for the C10,<br />

C30, C60, C100, C300D, C350D, C360D, and C370D appliances.<br />

A DLP policy is a set of conditions that the RSA Email DLP scanning engine uses to determine whether<br />

an outgoing message contains sensitive data and the actions that <strong>AsyncOS</strong> takes when a message<br />

contains such data.<br />

DLP policies include content matching classifiers developed by RSA, which the RSA Email DLP<br />

scanning engine uses to detect sensitive data in messages and attachments. The classifiers search for<br />

more than data patterns like credit card numbers and driver license IDs; they examine the context of the<br />

patterns leading to fewer false positives. For more information, see Content Matching Classifiers,<br />

page 11-20.<br />

Before RSA Email DLP scanning takes place, <strong>AsyncOS</strong>’s content scanning engine prepends the To,<br />

From, CC, and Subject headers to the message body, or any MIME parts that are tagged as content. This<br />

allows the RSA Email DLP scanning engine to scan these headers using the DLP policy’s content<br />

matching classifiers.<br />

If the DLP scanning engine detects a DLP violation in a message or an attachment, the DLP scanning<br />

engine determines the risk factor of the violation and returns the result to the matching DLP policy. The<br />

policy uses its own Severity Scale to evaluate the severity of the DLP violation based on the risk factor<br />

and applies the appropriate actions to the message. The scale includes five severity levels: Ignore, Low,<br />

Medium, High, and Critical. You decide what the Email Security appliance does with the message by<br />

specifying a message action for each severity level, except Ignore. For more information on message<br />

actions, see Message Actions, page 11-5.<br />

Email DLP policies contain the following information:<br />

Name and description of the policy.<br />

OL-25136-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!