Cisco Secure Access Help

PDF

Cisco Secure Access Help

Add an Email Rule to the Data Loss Prevention Policy

Want to summarize with AI?

Log in

Provides instructions for completing the Add an Email Rule to the Data Loss Prevention Policy workflow in Cisco Secure Access. You must have full Admin user permission in Secure Access.


The Secure Access Email DLP capability integrates with Cisco's Email Threat Defense, which provides cloud native email security. The system inspects the content of outgoing emails (.eml files) and assesses the content against the criteria of email DLP rules. You configure an Email rule to set the criteria as to what triggers enforcement. If a data violation is detected, the rule's action is immediately enforced. If Secure Access detects a violation, the offending content is listed in the Data Loss Prevention Report.

An Email must have at least one of the following four criteria defined:

  • Data Classifications — Include email files that match data classification of your own making or a built-in data classification provided by Secure Access.
  • File Labels — Include emails that have attacments with specific file label names configured in the value of the files' document properties, or include emails with attachment files that have no file labels configured. (You cannot select both of these criteria in a single rule.) Secure Access scans for file labels on the following file types: .doc, .pdf, .rtf, .xls, .ppt, .odp, .ods, .odt, .pptx, .xlsx, .docx, and .eml.
  • File Size— Include email files meeting size requirements that you specify.
  • File Type— Include or exclude files of types that you specify.

Email DLP rules scan only outgoing messages processed by Cisco's Email Threat Defense. Violations can be triggered by material found in the email subject, message body, or attachments; a single email message may trigger multiple violations: one for the message subject and body, and one for each attachment.

Before you begin

Procedure

  1. Create a DLP Email Rule Step 1 — Establish General Settings

  2. Select Data Classifications to apply to the rule

  3. Make Files Control selections for the rule

  4. Select Senders whose emails would be included or excluded from scanning this rule

  5. Select Receivers whose emails would be included or excluded from scanning this rule

  6. Select an Action to be performed when data matches the rule

  7. For any destination you can enable and configure pop-up notifications for violations.

  8. For any destination you can enable and configure an email notification to be sent to users when a violation occurs


Create a DLP Email Rule Step 1 — Establish General Settings

This is the first step in the process to add an email rule to a DLP policy, in which you create the rule and establish its basic characteristics.

Before you begin

Procedure

  1. Navigate to Secure > Policy > Data Loss Prevention Policy, click Add Rule, and choose Email DLP Rule.

  2. In the Add New Email Rule area, enter a meaningful Rule Name and Description. Choose a Severity value from the drop-down based on the risk involved or importance within the ruleset. (Assigning severity values can help later on when you need to filter events in the Data Loss Prevention report.)

    Severity section with option to select the severity level

Create a DLP Email Rule Step 2 — Select Data Classifications

This is the second step in the process to add an email rule to a DLP policy, in which you select the data classifications to apply to the rule.

Before you begin

Procedure

  1. Under Data Classifications select where in scanned files you would like this rule to search for the data classifications that you choose:

    Data Classifications page showing options to define search criteria for selected data classifications

    Email Subject—Scans the subject line of the email.

    Message Body—Scans the message body of the email.

    Attachment Name—Scans the file names of attachments to the email

    Attachment Content—Scans the contents of attachments to the email.

  2. Select Data Classifications to apply this rule; you can choose data classifications of your own making or built-in data classifications provided by Secure Access. (See Manage Data Classifications and Built-In Data Classifications.) Hover over PREVIEW to view data identifiers associated with each data classification.

    Data Classifications section with options to select custom or built-in data classifications for applying this rule

Create a DLP Email Rule Step 3 — Select Files Controls

This is the third step in the process to add an email rule to a DLP policy, in which you select the files controls to apply to the rule.

In the Files Control area, choose the file filters to apply to this rule. You can apply filters for:

  • MIP and Titus Labels, or files that have no file labels associated with them. (You cannot select both of these criteria in a single rule.)

  • File Size

  • File Type

Before you begin

Procedure

  1. You can enable MIP and Titus Labels and add up to 10 case-sensitive file label names to apply to the rule.

    The rule will search for any of the configured label names in document properties of email attachements. This includes Microsoft Office Document Properties and Adobe PDF Document Properties. For Microsoft Office Document Properties , this includes only the Label Value field in the custom document properties.

    Secure Access can scan for file labels on the following file types: .doc, .pdf, .rtf, .xls, .ppt, .odp, .ods, .odt, .pptx, .xlsx, .docx, and .eml.

    Enabling MIP and Titus labels
  2. Choose File Size criteria.

    The File Size area has two use cases:

    • In a rule with only custom file size criteria, DLP applies the rule action to files that match the file size criteria, regardless of content. (This may be useful in situations where you want to exclude certain low-risk files below a certain size from inspection, so as not to waste processing time on insignificant events.)

    • In a rule that specifies a custom file size along with other criteria such as Data Classification, the DLP applies the rule action to files that match the other criteria within the file size specified up to the first 50 MB of plain text. (Secure Access does not scan file content beyond the first 50 MB regardless of the file size specified here.)

    In the File Size area choose from two options:

    • To scan up to the first 50 MB of plain text of all files that meet other criteria defined by this rule, enable the File Size toggle and do not select custom sizes. (A rule that uses this option must also specify Data Classifications.)

    • To specify the minimum and maximum size limits the system will scan for files that meet other inclusion criteria defined by this rule, if there are any, enable the File Size toggle and select custom size values. If the file size exceeds the first 50 MB of the file, Secure Access scans only up to the first 50 MB of plain text in the file. (I.e., if you specify a minimum file size greater than 50 MB, Secure Access will not scan for other criteria specified in the rule.)

      You can choose to apply the rule action only to files that are greater than a minimum size you specify, or to files that are within a range of sizes you specify. (If you specify a maximum size without specifying a minimum size, the minimum size defaults to 0.) You can specify file sizes in KB or MB.

    Files Control card with an option to customize the file size limit for scanning
  3. You can select the File Type filter, which causes DLP to apply the action to emails that match the other rule criteria as well as having file attachments that match file type inclusions or exclusions that you select.

    1. Click the toggle to enable file type filtering.

      Files Control card with an option to customize the file type for scanning
    2. To include file types, use the search box to search for file types or browse within the the lists for file types. Check the boxes for the file types to include--individually or by group. Selected file types appear on the right.

      Included File Types section with file types selected for inclusion
    3. To exclude file types, check Select file types for exclusion. Under Excluded File Types, use the search box to search for file types or browse within the lists for file types. Check the boxes for file types to exclude--individually or by group. Selected file types appear on the right.

      Excluded File Types section with file types selected for exclusion
  4. In the Unclassified Files area, click the toggle to include that have no labels associated with them.

    This includes Microsoft Office Sensitivity Labels and Adobe PDF Document Properties. For Microsoft Office Document Properties (or Titus labels) , this includes only the Label Value field in the custom document properties.

    Secure Access can scan for file labels on the following file types: .doc, .pdf, .rtf, .xls, .ppt, .odp, .ods, .odt, .pptx, .xlsx, .docx, and .eml.

    Including files with no labels

Create a DLP Email Rule Step 4 — Select the Senders

This is the fourth step in the process to add an email rule to a DLP policy, in which you select the senders whose emails would be included or excluded from scanning this rule.

Before you begin

Procedure

In the Senders area, choose to include all users, include specific users, or exclude specific users.
  • To scan all emails from all senders, select Include all users.

    Senders section with an option to include all users to scan all emails from all users
  • To scan emails from specific users, select Include specific users. You can choose one or more of the following options:

    • Select users

      Use the search box to search for Identities within your environment, or browse within the the lists for AD Groups and AD users. Check the boxes for the users to include--individually or by group. Selected users appear on the right.

      Senders section showing an option to scan emails from specific users
    • Add user domains

      Enter one or more unique web site addresses from which email may be sent.

      Senders section with an option to select specific domains for sending emails
    • Add user email addresses

      Enter one or more valid email addresses from which email may be sent.

      Senders section showing an option to select specific enail addresses for sending emails
  • You can choose to exclude selected users from the lists of senders you have included:

    1. Select Exclude specific users.

      Senders section with an option to exclude selected users from the lists of senders
    2. Choose one or more of the following options to select users to exclude:

      • Select users

      • Add user domains

      • Add user email addresses

      These options present the same mechanisms for selecting users as described for including users, above.


Create a DLP Email Rule Step 5 — Select the Recipients

This is the fifth step in the process to add an email rule to a DLP policy, in which you select the recipients whose emails would be included or excluded from scanning this rule.

Before you begin

Procedure

In the Recipients area, choose to include all users, include specific users, or exclude specific users.
  • To scan all emails from all recipients, select Include all users.

    Recipients section with an option to include all users to scan all emails from all users
  • To scan emails from selected recipients, you can choose one or more of the following options:

    • Select users

      Use the search box to search for Identities within your environment, or browse within the the lists for AD Groups and AD users. Check the boxes for the users to include--individually or by group. Selected users appear on the right.

      Recipients section showing an option to scan emails from specific users
    • Add user domains

      Enter one or more unique web site addresses to which email may be sent.

      Recipients section with an option to select specific domains for sending emails
    • Add user email addresses

      Enter one or more valid email addresses to which email may be sent.

      Recipients section showing an option to select specific enail addresses for sending emails
  • You can choose to exclude selected users from the lists of recipients you have included:

    1. Select Exclude specific users.

      Recipients section showing an option to select specific enail addresses for receiving emails
    2. Choose one or more of the following options to select users to exclude:

      • Select users

      • Add user domains

      • Add user email addresses

      These options present the same mechanisms for selecting users as described for including users, above.


Create a DLP Email Rule Step 6 — Select the Rule Action

This is the sixth step in the process to add an email rule to a DLP policy, in which you select an Action to be performed when data matches the rule.

Before you begin

Procedure

From the Action drop-down list, choose Monitor or Block.
  • Monitor- Detects and logs a DLP event for every email violating this rule's criteria

  • Block- Blocks delivery of every email violating this rule's criteria, and logs a DLP event.

Action section with an option to monitor or block content for this rule

Create a DLP Email Rule Step 7 — Enable and Configure Pop-Up Notifications for Violations

This is the seventh step in the process to add an email rule to a DLP policy, in which you may optionally select to display a pop-up notification to the end user when data matches the rule.

Before you begin

Procedure

  1. Under User Notifications, you can enable the Pop up Notifications option to display pop-up notifications of violations to the end user.

    Note
    If you have no real time rules with at least one endpoint channel selected under Destinations, the Pop up Notification option remains disabled.
    User Notifications section with an option to enable pop-up notifications
  2. Define the message to appear in the pop up dialog when files match a rule.

    • To use the default Pop Up Template:

      1. Click Default Notification.

      2. To preview the content of the pop up text, click on Preview Default Notification. You can review the text, but you cannot change it.

        Preview default pop-up message displaying the heading and message body
      3. Click CLOSE to close the preview.

    • To use a Custom Pop Up Template:

      1. Click Custom Notification.

      2. From the drop-down list, select an existing custom template, or choose CREATE NEW TEMPLATE. If you select an existing custom template, you can click Preview and Edit Custom Notification to review and change the template.

        User Notifications page showing options to create and edit custom pop ups
      3. When you choose to create or edit a custom template for pop up text you will see one of these two dialogs, which are almost identical:

        View New Custom Pop-up Template and Edit Custom Pop-up Template pages

        The Edit Custom Pop-up Template dialog includes a DELETE link which you can use to delete a custom template that is no longer needed. You cannot delete a template that is in use by any rule.

        To create a new template or change an existing template:

        1. Enter a unique Custom Template Name.

        2. Enter the heading text for the pop up in the Heading text box.

        3. Enter the message text for the pop up in the Message Body text box.

        4. Click SAVE to complete the changes.


Create a DLP Email Rule Step 8 — Enable and Configure Email Notifications for Violations

This is the seventh and final step in the process to add an email rule to a DLP policy, in which you may optionally select to configure and enable email notifications to send users when data matches the rule.

Before you begin

Procedure

  1. Under User Notifications you can enable and configure an email notification to be sent to a user who triggers a violation of the rule. You can use a default email template provided by the system, or create your own custom template.

    Note

    The system gets the "send to" address for the notification email from UPN field in the authenticated active directory. Some identity configurations may not be able to provide the end user's email address, in which case the system will be unable to send the email. These cases include:

    • The user uses network or tunnel identities, in which case the user's IP address will be available to the system, but not the email address.

    • The user did not authenticate through active directory, so the system has no information about the user.

    • The user's email address is not stored in the UPN field in the authenticated active directory.

    1. Enable Email messages.

      User Notifications section with an option to enable email notifications
    2. Choose the email template:

      To Use the Default Email Template:

      1. Click Default Email.

      2. To preview the content of the email that will be send to users, click on Preview Default Email. You can review the email subject line and text, but you cannot change it.

        Preview Default Email section displaying the email subject line and content
      3. (Optional) To send a test copy of the email to an address of your choosing, enter an address in Preview Test Email and click SEND PREVIEW to send the message. (By default the system uses the email address of the logged in user.)

      4. Click CLOSE to return to the Data Loss Prevention Policy page.

      To Use a Custom Email Template:

      1. Click Custom Email.

      2. From the drop down menu, select an existing custom template, or choose CREATE NEW TEMPLATE. If you select an existing custom template, you can click Preview and Edit Custom Email to review and change the template.

        User Notifications page showing an option to create new email template
      3. When you choose to create or edit a custom template for email notifications of policy violations you will see one of these two dialogs, which are almost identical:

        View New Custom Email Template and Edit Custom Email Template pages

        The Edit Custom Email Template includes a DELETE link which you can use to delete a custom template that is no longer needed. You may not delete a template that is in use by any rule.

        To create a new template or change an existing template:

        1. Enter a unique Custom Email Template Name.

        2. Enter an Email Subject Line.

        3. Enter the text of the email in the Email Body text box.

          The email text can include the following variables, which you must enclose in braces ( {} ):

          • {eventId} - The unique identifier the system generates for the policy violation event.

          • {detectedTimestamp} - The date and time the violation was detected, formatted as shown in this example: "Oct 1, 2023 at 14:04 UTC"

          • {actorName} - Name of the user whose action triggered the violation. (Secure Access gets this information from the authenticated Active Directory.)

          • {actorEmail} - Email address of the user whose action triggered the violation. (Secure Access gets this information from the authenticated Active Directory.)

          • {fileName} - Name of the data file that triggered the violation.

          • {ruleName} - Name of the rule that was triggered.

          • {matchedClassifications} - The data classifications associated with the violation. (See Manage Data Classifications.)

          • {destination} - URL or IP address of the intended destination for the monitored request.

          Note
          The system replaces a variable with blank text if there is no value assigned to the variable or if an invalid variable name appears within the braces.
        4. (Optional) To send a test copy of the email to an address of your choosing, enter an address inHere is my first draft of sd Preview Test Email and click SEND PREVIEW to send the message. (By default the system uses the email address of the logged in user.)

        5. Click SAVE.

  2. Click Save. All fields must have options selected to save.