Provides instructions for completing the Add an Email Rule to the Data Loss Prevention Policy workflow in Cisco Secure Access. You must have full Admin user permission in Secure Access.
The Secure Access Email DLP capability integrates with Cisco's Email Threat Defense, which provides cloud native email security. The system inspects the content of outgoing emails (.eml files) and assesses the content against the criteria of email DLP rules. You configure an Email rule to set the criteria as to what triggers enforcement. If a data violation is detected, the rule's action is immediately enforced. If Secure Access detects a violation, the offending content is listed in the Data Loss Prevention Report.
An Email must have at least one of the following four criteria defined:
- Data Classifications — Include email files that match data classification of your own making or a built-in data classification provided by Secure Access.
- File Labels — Include emails that have attacments with specific file label names configured in the value of the files' document properties, or include emails with attachment files that have no file labels configured. (You cannot select both of these criteria in a single rule.) Secure Access scans for file labels on the following file types: .doc, .pdf, .rtf, .xls, .ppt, .odp, .ods, .odt, .pptx, .xlsx, .docx, and .eml.
- File Size— Include email files meeting size requirements that you specify.
- File Type— Include or exclude files of types that you specify.
Email DLP rules scan only outgoing messages processed by Cisco's Email Threat Defense. Violations can be triggered by material found in the email subject, message body, or attachments; a single email message may trigger multiple violations: one for the message subject and body, and one for each attachment.
Before you begin
- You must have full Admin user permission in Secure Access. For more information, see Manage Accounts.
- You must install Cisco Secure Email Threat Defense.
- You must Integrate Email Threat Defense with Secure Access DLP.
Procedure
-
Select Senders whose emails would be included or excluded from scanning this rule
-
Select Receivers whose emails would be included or excluded from scanning this rule
-
For any destination you can enable and configure pop-up notifications for violations.
-
For any destination you can enable and configure an email notification to be sent to users when a violation occurs