The file does not contain sensitive data, but is marked as sensitive.
Problem
The file does not contain sensitive data, but is marked as sensitive.
Cause
Some of the possible reasons for this problem to occur are:
- Context based classification may have been enabled for the target. Thus, files downloaded from work domains/apps/emails will automatically be marked as sensitive.
- File mayhave been marked sensitive due to data identified by pre-defined or custom RegEx.
- File may have been marked sensitive due to data identified by fingerprinting.
Resolution
Disable context based classification
To disable context based classification, on the Endpoint DLP Plus console,
- Go to the Policies tab
- Select Policy Deployment
- Under Action, select Modify
- Select Data Leak Prevention
- Under Settings, disable "Mark the files created from enterprise apps or downloaded from corporate web-domains/email as sensitive by default"
Remove pattern from RegEx
If the pattern to be removed is a pre-defined pattern, then report it to ManageEngine.
To Report to ManageEngine
- Go to the Policies tab
- Click on your policy
- Under False Positives, select Data Classification
- Click on Report to ManageEngine and report
If the pattern is a custom one given by the user, it can be removed by the following steps:
- Go to the Policies tab
- Under Data Classification, select your data rule
- Modify it by deleting the custom rule that contains the RegEx pattern
Increase the match percentage in fingerprinting
Increasing the percentage of matching in fingerprinting may help increase the accuracy of the content matching. To do this,
- Go to the Policies tab
- Under Data Classification, select Modify
- Select Document Matching under New Rule
- Increase match percentage to the required percentage
Keywords:
Context based classification, fingerprinting, false positives