Help Center

Third-party software Contact us

Setting up DLP Policies

Data loss prevention (DLP) policy management involves identifying sensitive data to be monitored and enforcing controls that govern how such data is processed or transferred across your environment.

Common use cases include blocking instantly when:

  • Credit card numbers are sent in outbound emails.
  • A user uploads files containing classified documents to a SaaS platform.
  • Large datasets are copied to external devices after hours.

Current scope limitations

At present, DLP policy enforcement is limited to Outlook email. Support for additional communication channels will be added in subsequent releases.

Prerequisites for setting up a DLP policy

Ensure the following components are configured before creating a DLP policy.

Data source

Add a data source such as a domain or workgroup before proceeding, as DLP policies cannot inspect or enforce controls unless a target environment is defined.

  • Find the steps to add and manage a domain here.
  • Find the steps to add and manage a workgroup here.

Device group

Define the set of endpoint devices the DLP policy must apply to. Without a device group, the DLP policy has no scope and cannot be enforced on any endpoint.

Find the steps to add and manage a device group here.

Data identifier group

A data identifier group defines sensitive data to be secured by configuring detection logic using regex patterns and keyword sets along with match conditions. A data identifier group tells the policy which sensitive data to secure—without it, detection cannot occur.

  • Find the steps to create and manage a data identifier group here.
  • Find the steps to create and manage a data identifier here.

Steps to create a DLP policy

The steps below outline how to configure a DLP policy that prevents credit card information from being transmitted in Outlook email subject lines and body content:

  • Open the DataSecurity Plus console. On the Apps page, beside Best Practices, select Policy Management.
  • Select +Add Policy in the top right-corner of the page.
  • In the Pre-requisites for DLP Policy Configuration pop-up, verify that all required components are configured:
    • If all components are configured, click Continue Creating Policy.
    • If any components are not yet configured, configure them before proceeding.
  • On the Enter Policy Details page, enter the policy name, description, and select the severity level.

    Sample:

    Name: Protect Cardholder Data via Outlook for PCI-DSS

    Description: Restricts transmission of cardholder data through Outlook email for FIN-OPS, HR-Process, and Admin-Core endpoint groups.

    Severity: High

  • Click Next in the bottom right-corner of the page.
  • On the Define Policy Scope page, click +Add Device Group in the top right-corner.
  • In the Select Device pop-up, select the desired device groups and click Add.
  • Click Next.
  • On the Choose Detection Criteria page, click +Add Identifier Group in the top right-corner.
  • In the Choose Identifier Group pop-up, select the desired identifier group and click Add.

    Sample: Cardholder Data

  • Click Next.
  • On the Enforce Exit Point Control page, select Email Client as the communication channel. Under Supported Clients choose Outlook.

    Note: Only Outlook email clients are currently supported. Additional email clients will be added in future releases. Need support for a different email client? Let us know here.

  • Use the Response drop-down to select the desired action: Allow, Warn, or Block.
  • Use the toggle to enable or disable the use of additional filters for precise control. Using additional filters for granular protection, you can refine which emails containing sensitive data trigger the policy.

    For example, choose to act only on emails that:

    • Contain attached files with the classification label of Restricted or Confidential.
    • Include specific From, To, or CC addresses.
    • Contain specific keywords such as Critical or Intellectual Property in the subject line.
    • Have attachments above a specific file size or type.

    Note: When multiple filters are selected, all conditions must be met for the policy to respond.

  • Click Next. Review all details on the Finalize Policy page.
  • Click Save.

Now, the policy is active and will be listed under the DLP Policy page.

What happens when a policy is violated?

When an active event matches the conditions defined in a policy, the policy is considered to be violated and the configured response is carried out. The event is then raised as an incident in the Incident Management console for review and resolution.

Based on the number of false positives generated, you can tighten policy accuracy by adding more criteria or exclusion entities.

For more details on how the Incident Management console works, click here.

Managing DLP policies

You can edit, enable, disable, or delete existing policies from the DLP Policy page.

Note: Once deleted, policies cannot be recovered. If you plan to reuse a policy later, disable it instead of deleting it.

Managing multiple DLP policies

When you have more than one DLP policy configured, each policy is assigned a priority that determines the order in which they are evaluated. The policy at the top of the list holds the highest priority and is evaluated first. When a new policy is created, it is automatically assigned the highest priority, and all existing policies are moved down by one position accordingly. You can reorder policies at any time to reflect your preferred priority.

To update policy priority:

  • On the Apps page, beside Best Practices, click Policy Management.
  • On the DLP Policy page, use the drag handle on the left side of any policy to reorder it into the desired position.

You can also refer to the Priority column in the DLP policies table to understand the current order.

How to handle conflicting DLP policies

When an event matches more than one policy, each match is raised as a separate incident in the Incident Management console. When the configured responses between the matched policies differ, only the most restrictive response applies—for example, if one policy is set to Warn and another to Block, the Block response takes effect.

Don't see what you're looking for?

  • Visit our community

    Post your questions in the forum.

     
  • Request additional resources

    Send us your requirements.