CNBELGIN
asked on
McAfee DLP Rule Query
Hello Experts,
I'm hoping someone can help. Does anyone know how to configure a rule to capture evidence on all data copied to storage devices, such as usb external drives? I've created a "removable storage protection rule" in DLP to capture evidence, but I’m sure how to define "everything". I can only get it to work if I specify a text pattern to look for. HELP!!!
I'm hoping someone can help. Does anyone know how to configure a rule to capture evidence on all data copied to storage devices, such as usb external drives? I've created a "removable storage protection rule" in DLP to capture evidence, but I’m sure how to define "everything". I can only get it to work if I specify a text pattern to look for. HELP!!!
why don't you just disallow writing to removable media entirely?
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
In responce to David
We're also blocking storage devices, users need to request a bypass code. The above rule will then monitor their actions.
We're also blocking storage devices, users need to request a bypass code. The above rule will then monitor their actions.
nice, thanks for sharing
ASKER
Thanks guys the links that btan provided are worth reading.
noted and thanks!