Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage the Data Loss Prevention Policy

Want to summarize with AI?

Log in

Describes Manage the Data Loss Prevention Policy in Cisco Secure Access. It summarizes the behavior, configuration context, and operational considerations presented throughout the topic.


Tip

Secure Access Packages and Feature Availability

Not all of the features described here are available to all Secure Access packages. Information about your current package is listed on the Admin > Licensing page. For more information, see Determine Current Package. If you encounter a feature here that you do not have access to, contact your sales representative for more information about your current package. For more information, click Cisco Secure Access Packages.

The Data Loss Prevention (DLP) policy helps protect sensitive data uploaded to the web or transferred to external devices like a USB storage device, a Bluetooth device, a network share, or when a file is printed to a local or a network printer. It discovers and protects sensitive data stored and shared in your cloud-sanctioned applications.

You can configure the DLP policy with multiple DLP rules. Real Time DLP rules inspect web traffic passing through the proxy or files transferred to external devices like a USB storage device, a Bluetooth device, a network share, or when a file is printed to a local or a network printer. SaaS API-based rules ensure data protection of data in the cloud. AI Guardrails rules ensure data protection in prompts and responses exchanged with AI applications. Furthermore, DLP Administrators can initiate on-demand Discovery Scans to learn about all the files in the applicable cloud applications that contain matches with the selected Data Classifications. Email DLP rules provide DLP functionality to enhance protection provided to outgoing emails by Cisco's Secure Email Threat Defense.

  • Real Time Rules: are added to the policy to define which web proxy traffic or files to monitor (identities and destinations), the content or document properties to search for, and whether to monitor or block the specified content. For example, an office may want to monitor its network for file uploads that include credit card numbers, as the uploads are a breach of the company's privacy and security policies. A Real Time DLP rule designed to monitor the network and uploads to domains can block these files.

  • SaaS API Rules: operate by leveraging the APIs of the applicable cloud tenants to scan and look for data violations in the cloud-stored files. As files in the selected tenant change in content or context (with whom we share), Secure Access near-time assesses the changed file against this rule's criteria. If a match is made, this rule's action is immediately enforced.

  • AI Guardrails Rules indicate which generative AI applications to monitor for specific types of data: sensitive data, inappropriate content, or content that presents a safety or security risk. Prompts, responses, and files embedded within prompts exchanged with selected AI applications can be monitored and potentially blocked, depending on rule settings.

  • Email DLP Rules coordinate with Cisco's Secure Email Threat Defense, analyzing the content of outgoing cloud-native email and enhancing the protection Email Threat Defense provides by adding Data Loss Prevention. DLP scans email and monitors or blocks emails that match rule criteria that define violations. To use this feature, you must generate DLP API keys within Secure Access, and use those keys to enable DLP in Email Threat Defense. More more details, see Integrate Email Threat Defense with Secure Access DLP.

Data violations detected through DLP rules are logged as part of the unified Events view of the Data Loss Prevention Report.

Discovery Scans operate similarly to the SaaS API rules; they exercise the necessary cloud APIs to determine the files in the applicable cloud tenant that contain data matching any of the configured Data Classifications at the time the scan runs. Files containing matching data are considered to be in violation of the Discovery Scan.

The Discovery tab in the Data Loss Prevention Report lists the files in violation of the most recently initiated Discovery Scan. Additionally, DLP Administrators can quickly retrieve the reported offending files from any of the last 10 generated Discovery Scans.

Realtime DLP rules support scanning traffic isolated by the RBI (Remote Browser Isolation) in the outbound direction, in addition to scanning non-isolated HTTPs traffic. When the system detects a DLP violation in RBI traffic, a pop-up dialog appears in the user's browser indicating the content has been blocked due to a potential data security violation.

Real Time rules, SaaS API rules, AI Guardrails rules, Email rules, and Discovery Scans all support scanning embedded files.

Limitations

  1. The rate limit is dependent on vendor SLA, which is usually up to 10 RPS for Microsoft 365 and up to 20 RPS for Google Drive.
    • The Discovery Scan can scan up to 36,000 files per hour and 864,000 files per day with an average file size of 1MB.

    • The incremental scan and Discovery Scan share the same rate limits, therefore, file changes (i.e. incremental) during the Discovery Scan are counted and have an effect on the Discovery Scan throughput.

    • An org that triggers more than 864k events per day will be at risk of not having all their events scanned.

  2. Triggering a Discovery Scan should take place around 24 hours after the tenant authorization, as the system needs time to evaluate and enumerate the users in the organization. Any triggering beforehand might not include all users and hence, the system is unable to scan all files.
  3. The DLP scans the plain text of files up to 50 MB.
  4. DLP scans archives as well as files containing embedded files. For these, DLP can extract and scan content for up to 100 files nested up to 10 levels deep.
  5. Revoke share for internal or external works only for organizations with one domain in Google Drive due to Google API limitation.

Best Practices for the Data Loss Protection Policy

Some of the Data Loss Prevention policy's built-in identifiers have the potential to produce false positives if not customized to narrow the scope of the inspection. The following are recommended to reduce the number of false positives in these classifications. For more information on customizing an identifier, see Copy and Customize a Data Identifier.

Threshold

The default threshold for built-in identifiers without tolerance is 1. This means that the policy will search for content where the identifier is met only once within a file. Increasing the threshold will scan content for instances where the identifier is met more than once, creating fewer false positives for each individual instance of the identifier. A threshold of 10, for example, only monitors or blocks a file if 10 instances of the identifier are found in the file.

Proximity Terms

Proximity keywords reduce false positives by requiring identifiers to match within 10 terms of specified words.

For example, a Canadian bank account identifier will search for a pattern matching Canadian bank account numbers and transit numbers. A document containing several random numbers matching that pattern could produce false positives, however, if proximity terms such as "Canada" and "bank" are added to the customized identifier, the scope of the inspection is reduced.


Supported File and Form Types

The Data Loss Prevention policy can monitor or block the data being uploaded to the web. The policy discovers and protects sensitive data contained in your cloud-sanctioned applications. The DLP scans the plain text of files up to 50 MB. DLP also scans archives and files containing embedded files. For these, DLP can extract and scan up to 100 files, nested up to 10 levels deep. Secure Access scans all files uploaded through the Secure Access SWG proxy that match the criteria for Real Time rules and scans files stored in Secure Access authorized cloud tenants. It performs a deeper analysis for these mime types:

MIME Type File Type Supported for Internet Traffic Supported for Private Traffic
application/catia CATIA_CAD Yes
application/coreldraw COREL_DRAW Yes
application/dca-fft IBM DCA/FFT Yes
application/dca-rft IBM DCA/RFT Yes
application/dicom DICM Yes Yes
application/gzip GZ Yes Yes
application/illustrator ADOBE_ILLUSTRATOR Yes
application/java-archive JAVA_ARCHIVE Yes Yes
application/msword Word .doc, .docx Yes Yes
application/pdf PDF Yes Yes
application/postscript Postscript .ps Yes
application/pro-e PRO_ENGINEER Yes
application/rtf RTF Yes Yes
application/sldworks SOLIDWORKS Yes
application/x-tar POSIX_TAR Yes Yes
application/vnd.apple.keynote Apple iWork Keynote .key Yes
application/vnd.apple.keynote.13 APPLE_KEYNOTE Yes
application/vnd.apple.numbers Apple iWork Numbers .numbers Yes
application/vnd.apple.pages Apple iWork Pages .pages Yes
application/vnd.framework3 FRAMEWORK_SPREADSHEET Yes
application/vnd.hancell HANCOM_OFFICE_HANCELL Yes
application/vnd.hp-pcl Printer Command Language Yes
application/vnd.lotus-1-2-3 LOTUS_1_2_3 Yes
application/vnd.ms-cab-compressed MICROSOFT_CABINET_ARCHIVE Yes
application/vnd.ms-excel Excel .xlsx Yes Yes
application/vnd.ms-excel.addin.macroenabled.12 Excel Add-In with Macro .xlam Yes

application/vnd.ms-
excel.sheet.binary.macroenabled.12

Excel Binary with Macro .xlsb Yes

application/vnd.ms-
excel.sheet.macroenabled.12

Excel with Macro .xlsm Yes
application/vnd.ms-excel.template.macroenabled.12 Excel Template with Macro .xltm Yes
application/vnd.ms-resourcefile Windows Resource File Yes

application/vnd.openxmlformats-
officedocument.spreadsheetml.template

Excel Template .xltx Yes

application/vnd.openxmlformats-
officedocument.wordprocessingml.template

Word Template .dotx Yes
application/vnd.ms-outlook Microsoft Outlook .msg Yes

application/vnd.ms-outlook-
olk15-msgsource

Microsoft Outlook for Mac Message Source Yes
application/vnd.ms-paint IMAGE_MS_PAINT Yes
application/vnd.ms-powerpoint PowerPoint .ppt Yes Yes
application/vnd.ms-visio.drawing MICROSOFT_VISIO_DRAWING Yes

application/vnd.ms-
word.document.macroenabled.12

Word with Macro .docm Yes Yes
application/vnd.ms-works MICROSOFT_WORKS Yes
application/vnd.ms-xpsdocument MICROSOFT_XPS Yes Yes

application/vnd.oasis.opendocument.
presentation

OpenDocument Presentation .odp Yes

application/vnd.oasis.opendocument.
spreadsheet

OpenDocument Sheet .ods Yes
application/vnd.oasis.opendocument.text OpenDocument Word .oth Yes

application/vnd.openxmlformats-
officedocument.presentationml.presentation

PowerPoint .pptx Yes Yes
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet Excel .xlsx Yes
application/vnd.paradox PARADOX_DATABASE Yes
application/vnd.prowrite Professional Write Yes
application/vnd.rar RAR archive format .rar Yes Yes
application/vnd.tcpdump.pcapng PCAP Yes Yes
application/vnd.visio MICROSOFT_VISIO Yes
application/vnd.wordperfect; version=4.2 WordPerfect 4.2 Yes Yes
application/vnd.wordperfect; version=5.0 WordPerfect 5.0 Yes Yes
application/vnd.wordperfect; version=5.1 WordPerfect 5.1 Yes Yes
application/vnd.wordperfect; version=6.x WordPerfect 6 Yes Yes
application/vnd.wordstar; version=5 WordStar 5 Yes
application/vnd.wordstar; version=2000 WordStart 2000 Yes
application/vnd.xy-write XyWrite Yes
application/x-dbf DBASE_DATABASE Yes
application/x-hwp Hangul Yes Yes
application/x-isys-index ISYS_INDEX_FILE_ISYS_IX Yes
application/x-mathcad MATHCAD Yes
application/x-msaccess MICROSOFT_ACCESS_DATABASE_MDB Yes Yes
application/x-mswrite Windows Write Yes
application/x-step STEP_3D_CAD Yes
application/x-adobe-indesign ADOBE_INDESIGN Yes
application/x-ace-compressed ACE_ARCHIVE Yes
application/x-alz-compressed ALZ_ARCHIVE Yes Yes
application/x-archive UNIX_AR_ARCHIVE Yes
application/x-arj ARJ_ARCHIVE Yes Yes
application/x-bzip bz Yes
application/x-bzip2 bz2 Yes
application/x-compress COMPRESS_ARCHIVE_Z Yes
application/x-corelpresentations COREL_PRESENTATION Yes
application/x-cpio CPIO_UNIX_ARCHIVE Yes
application/x-dosexec+rar RAR_ARCHIVE_SFX Yes
application/x-dosexec+zip ZIP_ARCHIVE_SFX Yes
application/x-dosexec+7z SEVEN_ZIP_ARCHIVE_SFX Yes
application/x-egg-compressed EGG_ARCHIVE_EGG Yes Yes
application/x-iso9660-image ISO_DISK_IMAGE Yes
application/x-jt JT_CAD Yes
application/x-lha LHA_ARCHIVE Yes
application/x-lzh LZH_ARCHIVE Yes
application/x-msbinder MICROSOFT_BINDER Yes
application/x-ms-object Microsoft Outlook MSO object Yes
application/msonenote ONE Yes Yes
application/x-ms-outlookexpress Microsoft Outlook Express Yes
application/x-quattro-pro QUATTRO_PRO_SPREADSHEET Yes
application/x-rpm RPM_PACKAGE Yes
application/x-stuffitsea STUFFIT_SELF_EXTRACTING_ARCHIVE Yes
application/x-stuffit STUFFIT_ARCHIVE Yes Yes
application/x-stuffitx STUFFIT_X Yes
application/x-tar Tape archive .tar Yes
application/x-xz XZ_ARCHIVE Yes
application/x-7z-compressed 7 Zip Format .7z Yes Yes
application/zip Zip archive .zip Yes Yes
audio/mpeg AUDIO_MPEG Yes
image/bmp BMP Yes Yes
image/brk IMAGE_BROOKTROUT_FAX Yes
image/cgm CGM Yes
image/emf * EMF Yes
image/iff IMAGE_IFF Yes
image/jpeg JPEG Yes Yes
image/jpeg JPG Yes Yes
image/gif GIF Yes Yes
image/png PNG Yes Yes
image/sgi SGI_IMAGE_FILE Yes
image/starview-metafile STARVIEW_METAFILE_SVM Yes
image/svg+xml SCALABLE_VECTOR_GRAPHIC Yes
image/tiff TIFF Yes Yes
image/vnd.adobe.photoshop PSD Yes Yes
image/vnd.dgn

INTERGRAPH_MICROSTATION_CAD_
DGN

Yes
image/vnd.dwg AUTODESK_AUTOCAD Yes Yes
image/vnd.dxf AUTOCAD_DXF Yes
image/vnd.imnet-c4 IMNET_MEDICAL Yes
image/vnd.microsoft.icon ICO Yes Yes
image/vnd.ms-modi IMAGE_MDI Yes
image/vnd.wap.wbmp WBMP Yes
image/webp WEBP Yes
image/wmf * WMF Yes
image/wmf WINDOWS_METAFILE_WMF Yes Yes
image/x-bitmap XBM Yes
image/x-cals CALS Yes
image/x-macpaint IMAGE_MAC_PAINT Yes
image/ncr IMAGE_NCR Yes
image/x-paintshoppro IMAGE_PAINTSHOP_PRO Yes
image/x-pcx PCX Yes
image/x-pict PICT Yes
image/x-portable-bitmap PBM Yes
image/x-tga TGA Yes
image/x-xpixmap XPM Yes
image/x-xwindowdump

IMAGE_X_WINDOW_SYSTEM_SCREEN
_DUMP

Yes
message/rfc822 E-mail Yes Yes
model/iges IGS_CAD Yes
model/prt PRO_ENGINEER_MODEL Yes
model/vnd.dwf AUTODESK_WHIP Yes
model/vnd.parasolid.transmit.binary PARASOLID_MODEL_PART Yes
model/x.stl-ascii STEREOLITHOGRAPHY_CAD_TEXT Yes
model/x.stl-binary STEREOLITHOGRAPHY_CAD_BINARY Yes
multipart/related Microsoft Web Archive Yes
text/csv CSV Yes Yes
text/html HTML/XML Yes
text/obj-cad OBJ_3D_IMAGE Yes
text/plain Plain text .txt Yes
text/plain UNIX_SCRIPT Yes Yes
text/rtf RTF Yes
text/tab-separated-values TSV Yes
text/url URL Yes

* EMF and WMF are wrapper file types. In DLP reports, these files display as the types of the files they contain: PNG or JPG.

Real Time DLP rules can scan the content of all applicable web requests of these form types:

  • JSON

  • XML

  • URL-encoded

  • Multipart form

Note
The DLP engine decompresses and scans 10 levels of sub-folders in the zipped and archive types for both Real time and SaaS API DLP.
Note

Optical Character Recognition (OCR) supports scanning and extracting text from supported image file types, including BMP, BRK, CGM, DCX, EMF, GEM, GIF, IFF, IMNET, JEDICS, JPEG, JPG, JPK, JXR, MACPAINT, MDI, MSPAINT, NCR, PBM, PCX, PICT, PNG, PSP, SVM, TGA, TIFF, WBMP, WEBP, WMF, and XWD. OCR also scans from scanned PDFs and images embedded in files such as Excel spreadsheets, PowerPoint presentations, Word documents, PDFs, and ZIP files.

Secure Access supports scanning images with a minimum resolution of 300 dpi and a minimum font size of 10 points. Once text is extracted, it is scanned against all configured DLP rule types for violations. OCR supports multiple languages. For more information on configuring OCR scanning, see Manage Global Settings.


Understand Exclusions in a Real Time Rule

The Data Loss Prevention policy evaluates all active Real Time rules against the web requests in your environment. Upon determining that a web request matches the identity and destination criteria of a Real Time rule, Secure Access then inspects the web request for matches with the rule's configured data classifications and file labels. Exclusions enable you to narrow your data criteria monitoring to specific applications and destinations. For example, if you have the rule to monitor data classifications for an application, but want to exclude some domains or URLs from being scanned, you can exclude a destination list with those domains. Traffic through that application will be scanned with the exception of the destination list excluded.

Within the context of a Real Time rule, exclusions will always override inclusions. For example, if a rule states that a domain on one list is excluded but the same domain is included on another destination list, the domain will automatically be excluded from the rule.


Supported Applications

The Real Time DLP rules inspect the content of all Secure Access proxied web requests matching the resources and destinations selected in the Real Time rules of the Data Loss Prevention (DLP) policy. When a Real Time DLP rule is configured with Select Destination Lists and Applications for Inclusion, Secure Access scans for data violations every web request matching the rule's applicable resources and targeting a destination matching the rule-configured destinations. A web request can be a web form or a file upload. File uploads can be scanned for matches with the selected data classifications in the file content, file name, or either. Moreover, a file upload can be scanned for the presence of document properties matching the rule's File Labels settings. For more information, see Add a Real Time Rule to the Data Loss Prevention Policy.

Verified applications also support other workflows besides file uploads. For example, if the rule is configured to Select Destination Lists and Applications for Inclusion and Yahoo Mail is chosen as an application to scan for content, the policy can scan for file uploads, emails sent, and draft emails saved. Violations within these workflows are then blocked or monitored, depending on the action selected in the rule. However, some applications have limitations when scanning for file names of file uploads. For example, the DLP policy can scan Dropbox for file uploads, but the file name can not be scanned.

The DLP Real Time rules support thousands of applications, divided into categories for ease of reference. Before January of 2024, DLP supported a more limited set of applications; the table below lists those applications and the limitations on their support. These applications appear in the GUI with the notation (Vetted), as shown in the example below:


Destinations page showing applications marked as Vetted

The list of apps marked Vetted in the GUI, and their workflow limitations, is listed below:

Application Supported Workflows File Name Limitations
Box Cloud Storage File upload
ChatGPT Create conversation
OpenAI ChatGPT API Request and Response of Chat and Completions
Concur Invoice Receipt upload
Confluence File upload; edit a file
Note
To scan file uploads, you must select Atlassian and Confluence as destinations for the DLP rule.
DLPTest.com Submit test message; File upload
Dropbox File upload; File upload add comment; File upload update comment.
Note
Dropbox Paper is not supported using Real Time DLP, but may be supported using SaaS API DLP.
File names of file uploads are not scanned.
Note
Depending on the mechanism used to upload large files, such as chunked uploads by platforms like Dropbox, the DLP engine may not be able to fully scan the document for policy violations.
Facebook Messenger Upload a file to chat
Gmail Send email; attach a file; save a draft; send an email (classic); save a draft (classic)
Jira Create a ticket (epic/story/task/subtask/bug/customer issue/customer request) description; upload an attachment to a newly created ticket (Atlassian must also be selected); add a comment to a ticket; edit a comment in a ticket; edit description.
Note
To scan file uploads, you must select Atlassian and Jira as destinations for the DLP rule.
LinkedIn SlideShare File upload; publish content after a file upload; edit a published slide; edit privacy settings of a post; report content as inappropriate; upload thoughts and ideas on a slideshare; like a thought or slide; upload files from a Cloud app (Dropbox, GDrive, Box, Gmail, OneDrive); share content using linkedIn, Facebook, or Twitter
Monday Create workspace; create board; add item-update with file upload; add an item–update reply with file upload; add a message to Text column; add text to Long Text column; add an update with a file upload to a sub-item; reply to a sub-item update with a file upload; add a local file to File column; add an email address or text to Email column; upload a file to a shared form; add text to the dashboard text widget;
PasteBin Post a message
SalesForce File upload; upload file via chatter; write a post in chatter; write a note;
ServiceNow Service management post incident; service automation post incident
ShareFile Create note; create request list; upload a file to a task; create a task; add task comment; send an invite to a new user; share a file; file upload; submit a form; remote upload a form; create a file drop; share a file via email; send an email File names of files uploaded to ShareFile storage are not scanned.
Slack File upload; post a message in a channel
SmartSheet File upload; upload attachment to a form; add comment to a form
WeTransfer File upload; upload a file to a message File names of files uploaded to WeTransfer are not scanned.
WorkDay HCM Add an address; edit an address; add text to a field; upload a file
Yahoo Mail Upload file; send an email; save a draft