Dqr95gvqayxl DLPAdmin10.0LabGuideE Learning1
Dqr95gvqayxl DLPAdmin10.0LabGuideE Learning1
Dqr95gvqayxl DLPAdmin10.0LabGuideE Learning1
Forcepoint DLP
Lab Guide 1
All other trademarks used in this document are the property of their respective owners.
This document may not, in whole or in part, be copied, photocopied, reproduced, translated, or
reduced to any electronic medium or machine-readable form without prior consent in writing
from Forcepoint. Every effort has been made to ensure the accuracy of this manual. However,
Forcepoint makes no warranties with respect to this documentation and disclaims any implied
warranties of merchantability and fitness for a particular purpose.
Forcepoint shall not be liable for any error or for incidental or consequential damages in
connection with the furnishing, performance, or use of this manual or the examples herein. The
information in this documentation is subject to change without notice.
These are the credentials that you will use during your training.
You want to know how to find your Data Loss Prevention information.
Tasks:
2. Double click the mRemoteNG shortcut and the mRemote application will load.
3. Double-click the Security Manager link in the Connections tab on the left-hand side of the
window.
You have renewed your subscription to Forcepoint DLP and have received the subscription
XML file. You want to update your subscription in FSM.
Tasks:
You want to know what components are configured in your Forcepoint DLP environment.
Tasks:
Now that you know what a policy is and how it works, you want to detect when people share
patient medical forms using Forcepoint DLP.
Tasks:
Having set up the policy and monitored it for three months, all users have received training
about sharing patient data. You want to block sharing of patient medical forms.
Task:
3. Return to the Security Manager and view the latest incident report. If the incident does not
appear immediately, click the refresh button in the top right-hand corner.
Now that you have monitored the policy, you want to change the action plan of all the rules in
the policy to “block” as efficiently as possible.
Task:
Having set up a policy to monitor patient medical forms, you want to send an email to key
people when a policy is triggered to tell them who triggered it and how.
Tasks:
5. Click OK to save the changes to the notification settings. This is another piece of essential
configuration.
You want to stop credit card details being shared outside your organization.
Tasks:
4. In the Severity & Action section, leave the severity as High and the action as Block.
3. In the Severity & Action section, leave the severity as Medium and the action as Block.
4. Click OK in the bottom right to save your configuration.
5. Click Deploy to deploy your quick policy.
Now that you have a policy set up, you want to know who the managers of the users are, so that
you can tell them when the policies are triggered.
Tasks:
Having imported your user directory, you want to email notifications to the user’s manager when
they trigger a policy.
Tasks:
10. Click the Notification Body tab to edit the message body of the template.
11. In the message to user, enter “Severity:” at the end of the message.
13. Click OK to save the changes to the notification settings and body.
Update all the rules in the US PHI policy to Severity High and Action Plan Block All.
For further help see:
Updating Multiple Forcepoint DLP Policies (hack stack) or
Update rules of multiple policies (administrator help).
Configure the Email DLP Policy to monitor USA Payment Card Industry (PCI DSS)
data. Configure the policy to monitor for Attachment Type: Various Executables
Formats and drop the attachments, (scroll down for Severity & Action).
For further help see:
Configuring outbound and inbound email DLP attributes (administrator help).