Link to home
Start Free TrialLog in
Avatar of CNBELGIN
CNBELGIN

asked on

McAfee DLP Rule Query

Hello Experts,

I'm hoping someone can help. Does anyone know how to configure a rule to capture evidence on all data copied to storage devices, such as usb external drives?  I've created a "removable storage protection rule" in DLP to capture evidence, but I’m sure how to define "everything". I can only get it to work if I specify a text pattern to look for. HELP!!!
Avatar of David Johnson, CD
David Johnson, CD
Flag of Canada image

why don't you just disallow writing to removable media entirely?
SOLUTION
Avatar of btan
btan

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of CNBELGIN
CNBELGIN

ASKER

In responce to David

We're also blocking storage devices, users need to request a bypass code. The above rule will then monitor their actions.
nice, thanks for sharing
Thanks guys the links that btan provided are worth reading.
noted and thanks!