27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 11 Data Loss Prevention<br />

Filtering by Senders and Recipients<br />

Filtering by Attachment Types<br />

Filtering by Message Tag<br />

OL-25136-01<br />

You can limit the DLP policy to scan messages with specific recipients or senders in one of the following<br />

ways:<br />

Full email address: user@example.com<br />

Partial email address: user@<br />

Setting the Severity Levels<br />

All users in a domain: @example.com<br />

All users in a partial domain: @.example.com<br />

You can separate multiple entries using a line break or a comma.<br />

For an outgoing message, <strong>AsyncOS</strong> first matches the recipient or sender to an outgoing mail policy. After<br />

the recipient or sender is matched, RSA Email DLP then matches the sender or recipient to the DLP<br />

policies enabled for the mail policy.<br />

You can limit the DLP policy to messages with specific attachment types. Attachments are first extracted<br />

using <strong>AsyncOS</strong>’s content scanning engine and then the content of the attachment is scanned by the RSA<br />

Email DLP scanning engine. The appliance provides a number of predefined file types for scanning, but<br />

you can also specify file types that are not listed. If you specify a file type that is not predefined,<br />

<strong>AsyncOS</strong> searches for the file type based on the attachment’s extension. You can limit RSA Email DLP<br />

scanning to attachments with a minimum file size in bytes.<br />

If you want to limit a DLP policy to scanning messages containing a specific phrase, you can use a<br />

message or content filter to search outgoing messages for the phrase and insert a custom message tag<br />

into the message. When creating a DLP policy, select the message tags you want to use for filtering<br />

outgoing messages. For more information, see Content Filter Actions, page 6-12 and the “Using<br />

Message Filters to Enforce Mail Policies” in the Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> for Email Advanced<br />

<strong>Configuration</strong> <strong>Guide</strong>.<br />

If RSA Email DLP scanning engine detects a DLP violation, it calculates a risk factor score that<br />

represents the severity of the violation, ranging from 0 to 100. The policy compares the risk factor score<br />

to the Severity Scale. The Severity Scale includes five severity levels: Ignore, Low, Medium, High, and<br />

Critical. The severity level determines the actions taken on the message. By default, all severity levels<br />

(except Ignore) inherit the settings of the higher severity level; the High severity level inherits the<br />

settings from Critical, Medium inherits from High, and Low inherits from Medium. You can edit the<br />

level to specify different actions for different severities.<br />

For information on how the DLP scanning engine calculates a risk factor, see Understanding How RSA<br />

Email DLP Works, page 11-8.<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

11-15

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!