27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

DLP Policy Manager for Enterprise Manager DLP Policies<br />

11-30<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

Chapter 11 Data Loss Prevention<br />

The DLP Policy Manager shows the RSA Enterprise Manager DLP policies currently in use on the Email<br />

Security appliance. You can use the Manager to enable or disable individual DLP policies on the Email<br />

Security appliance. Any outgoing mail policies assigned to the disable DLP policy will skip the policy<br />

when evaluating messages for DLP violations.<br />

Figure 11-10 Enterprise Manager DLP Policies in DLP Policy Manager<br />

If the Email Security appliance has not received the DLP policies from Enterprise Manager, it will<br />

continue to use any existing RSA Email DLP policies until it receives a data package with the new<br />

policies from Enterprise Manager.<br />

RSA Enterprise Manager and Language Support<br />

Quarantines<br />

The Email Security appliance displays any data it receives from RSA Enterprise Manager in the language<br />

that was used in Enterprise Manager. The appliance does not display this information in the language<br />

you selected for the appliance interface. This applies to DLP policies, classifiers, dictionaries, and<br />

anything else created in Enterprise Manager that the appliance receives in the data package. For example,<br />

if the DLP policies and classifiers from Enterprise Manager were written in English but the interface of<br />

the Email Security appliance is displayed in French, the Email Security appliance displays the name and<br />

descriptions of the DLP policies and classifiers from Enterprise Manager in English. The rest of the<br />

interface remains in French.<br />

If a message containing a DLP violation matches a DLP policy that requires the message to be<br />

quarantined, the Email Security appliance sends the message to the quarantine specified by the DLP<br />

policy’s message action. The user responsible for evaluating DLP violations can review the incident<br />

using Enterprise Manager and can then use Enterprise Manager to instruct the appliance to release or<br />

delete the message from the quarantine. If the message action requires the message to be encrypted on<br />

release, it is the Email Security appliance that encrypts the message, not Enterprise Manager.<br />

Users can view messages quarantined by Enterprise Manager using the Monitor > Quarantines page in<br />

the Email Security appliance’s GUI. Cisco recommends that users only release or delete messages with<br />

DLP violations from Enterprise Manager, not the local Email Security appliance’s GUI.<br />

Cisco also recommends the following procedures for using quarantines with Enterprise Manager:<br />

Use one or more dedicated quarantines for DLP violations.<br />

Set a timeout large enough for Enterprise Manager to complete its tasks.<br />

Be aware that Email Security appliance will still release or delete quarantine messages when the<br />

quarantine exceeds the allotted space.<br />

For more information on how quarantines work on the Email Security appliance, see the “Quarantines”<br />

chapter in the Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> for Email Daily Management <strong>Guide</strong>.<br />

OL-25136-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!