One of the greatest threats to any organization is data leak perpetrated by trusted employees and partners. To combat the ever-increasing insider threat, you need to monitor all file activities, especially file copy actions. With DataSecurity Plus, you can now audit, monitor, and alert on all file copy events.
Steps to audit and report on file copy-and-paste events:
- Download and install DataSecurity Plus.
- Open the DataSecurity Plus console.
- Navigate to the Endpoints tab. Go to Configuration > Sources > Devices.
- In the Configured Workstation(s) page, select Add Workstation(s) in the top-right corner.
- Select your domain.
- Select the + symbol next to the Select Workstation(s) text box, and add the workstations that you want to audit and secure.
- Choose File Copy Auditing.
- Select Install Agent and Finish.
- Navigate to Reports. Under Source Based Reports, choose File Copied Report.
- Select the desired time range over which file copy events are to be monitored using the Period drop-down.
- The report displays all files copied during local or remote access.
Steps to selectively monitor when sensitive or large files are copied:
- In the DataSecurity Plus console, navigate to the Endpoints tab.
- Go to Configuration > Settings > Audit Configuration.
- Choose Clipboard from the available audit profiles.
- Select Edit for the File Copy Auditing audit profile.
- The audit profile is predefined with an appropriate name, source, and description.
- Navigate to the Criteria section and add these filters under the Include tab:
- Actions: Files copied and files pasted.
- Users: All
- File classification*: Restricted
Note: Use other criteria such as File Type, File Size, File Name, and more to selectively monitor critical data being copied.
- Use the Exclude option to exempt trusted users, groups, or nonessential files from the file copied report.
- Click Save.
Steps to generate instant alerts when sensitive files are copied in bulk:
- In the DataSecurity Plus console, navigate to the Endpoints tab.
- Go to Configuration > Settings > Alert Configuration.
- Choose Clipboard from the available Alert Profiles.
- Select the Edit option for the Sensitive Files Copy Monitoring alert profile.
- The alert profile is predefined with an appropriate Name, Source, Description, and Severity.
- Navigate to the criteria section and add these filters under the Include tab:
- Actions: Files copied and files pasted.
- Users: All
- File classification*: Restricted
Note: Use other criteria such as File Type, File Size, File Name, and more to selectively monitor critical data being copied.
- Use the Exclude' option to exempt trusted users, groups, or nonessential files from the file copied report.
- Under the Threshold tab:
- Check Enable.
- Specify the desired threshold value (e.g., configuring "100 events in 1 minute by any source" will raise an alert when 100 or more files are copied/pasted in under a minute.)
Note: The threshold limit can be customized to your organization's needs.
- Under the Response tab:
- Select Email, and check Enable email notification.
- Specify one or more email addresses you would like to send alerts to.
- Set email Priority to High.
- Add in an appropriate Subject and Message for your email.
- Click Save.
You have now successfully configured DataSecurity Plus to audit, alert, and respond to sensitive files being copied.
*File classification: Files need to be classified manually based on their sensitivity as Public, Internal, Sensitive, or Restricted.