{"id":5202,"date":"2022-02-01T12:31:37","date_gmt":"2022-02-01T09:31:37","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=5202"},"modified":"2022-02-08T18:08:46","modified_gmt":"2022-02-08T15:08:46","slug":"getting-started-with-content-aware-protection","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/getting-started-with-content-aware-protection\/","title":{"rendered":"Getting Started with Content Aware Protection"},"content":{"rendered":"<div class=\"preformatted-content\">\n<p>TL;DR<\/p>\n<ul>\n<li aria-level=\"1\">Content Aware Protection allows Administrators to set up and enforce strong content filtering policies for selected users, computers, groups, or departments and take control over the risks posed by accidental or intentional file transfers of sensitive company data.<\/li>\n<li aria-level=\"1\">Controls can be placed around predefined data (for example, PII, PHI, email addresses, passport numbers, credit card numbers, etc.) or custom data (accounting documents, technical data, customer databases).<\/li>\n<li aria-level=\"1\">CAP policies can be applied to monitor various exit points, including portable storage devices, network shares, email, transfers to cloud file services, printers, etc. It can also be used to prevent sensitive data from being captured via a copy and paste and screen capture.<\/li>\n<li aria-level=\"1\">We recommend building a \u201cReport only\u201d policy first. This will allow you to monitor how files\/data are being used across endpoints. This will help to ensure blocking policies are effective without damaging productivity.<\/li>\n<\/ul>\n<\/div>\n<p><a href=\"https:\/\/www.endpointprotector.com\/solutions\/content-aware-data-loss-prevention\" target=\"_blank\" rel=\"noopener\">Content Aware Protection<\/a> (CAP) is one of Endpoint Protector\u2019s key modules. As data is moved from the employee endpoint to cloud applications and USB drives or through email and enterprise messaging applications, CAP inspects the content to ensure it doesn\u2019t breach your data protection policies. For example, you may want to restrict employees from sharing customer PII via email or being able to upload it to cloud storage services. CAP can also prevent transfers via copy and paste and print screens.<\/p>\n<p>In this Academy Guide, we\u2019ll cover the basic settings and how to get started with Content Aware Protector.<\/p>\n<p>To best understand Content Aware Protection (CAP), consider this module similar in behavior to an Antivirus\u2019 Active Scan feature.\u00a0 CAP is looking at file activity as it happens and checking the content to ensure any sensitive data subject to a policy is not moved beyond the employee endpoint.<\/p>\n<p>Just like a <a href=\"https:\/\/www.endpointprotector.com\/solutions\/device-control\" target=\"_blank\" rel=\"noopener\">Device Control<\/a> policy, a CAP policy continues to protect the endpoint even when it\u2019s offline.<\/p>\n<p>Before launching Content Aware Protection, we always advise starting out with a \u201cReport only\u201d Content Aware Protection Policy.\u00a0 This is your first step in understanding the movement of files across your endpoints and the topic of this Academy Guide.<\/p>\n<h2>Build a CAP report to understand file movement<\/h2>\n<p>Create a \u201cReport only\u201d CAP policy by navigating to <strong>Content Aware Protection<\/strong> &gt; \u2018Content Aware Policies.\u2019<\/p>\n<p>Click the \u2018Create Custom Policy\u2019 button, define the OS Type, provide a Policy Name (it is suggested to include \u201cReporting\u201d or \u201cReport only\u201d within the Name or Description), and be sure to select <strong>Report only<\/strong> for the \u2018Policy Action:\u2019 field.\u00a0 Scroll to the bottom of this page and choose the <strong>Save button<\/strong> &#8211; this action will return you to the policies viewing window.\u00a0 If you manage more than one Operating System type in the environment, follow this same procedure to create the policy framework(s) for the other platform(s).<\/p>\n<p>After your Report, only policy framework(s) has been established, select your first policy within the window and choose the icon for edit.\u00a0 This \u2018Edit\u2019 icon can be found on the right-hand side of the policy (look for the pen and paper icon). This will bring you back to the \u2018Edit Policy\u2019 page, where you will select the Exit Points of focus and the items you may later deliver blocking restrictions against.<\/p>\n<p><strong>Note<\/strong> &#8211; the terminology used in this policy is \u2018Denylists,\u2019 but you are implementing no restrictions. Since the CAP feature module focuses on in-motion objects, it consumes minimal endpoint resources. Also, it is best to set only the variables found in a given environment where agents are to be installed. This will ensure no unnecessary processing takes place at the point of detection.<\/p>\n<p>The <strong>Applications<\/strong> tab under \u2018Exit Points\u2019 is commonly used for common email clients and\/or web browsers in a given environment. It also allows you to monitor enterprise messaging apps and file-sharing services. Alongside this, the <strong>Storage Devices<\/strong> tab can be used if you intend to later restrict the transfer of sensitive files to storage media.<\/p>\n<p><a href=\"https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareExitPoints.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-5213\" src=\"https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareExitPoints-560x308.png\" alt=\"\" width=\"1200\" height=\"659\" srcset=\"https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareExitPoints-560x308.png 560w, https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareExitPoints-1024x562.png 1024w, https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareExitPoints-768x422.png 768w, https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareExitPoints-1536x844.png 1536w, https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareExitPoints-2048x1125.png 2048w, https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareExitPoints-1568x861.png 1568w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/a><\/p>\n<p><em>Click the image for full resolution.<\/em><\/p>\n<p>The Denylists section provides methods for determining which objects to focus classification and determination on.\u00a0 If it is desired to audit activity around given files, the \u2018File Type\u2019 tab will provide several options for common files types in systems.\u00a0 If the focus is more regulatory-bound, using the \u2018Predefined Content\u2019 tab may be more appropriate.<\/p>\n<p><a href=\"https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareDenylists.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-5214\" src=\"https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareDenylists-560x316.png\" alt=\"\" width=\"1200\" height=\"676\" srcset=\"https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareDenylists-560x316.png 560w, https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareDenylists-1024x577.png 1024w, https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareDenylists-768x433.png 768w, https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareDenylists-1536x866.png 1536w, https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareDenylists-2048x1154.png 2048w, https:\/\/static.endpointprotector.com\/blog\/2022\/02\/ContentAwareDenylists-1568x884.png 1568w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/a><\/p>\n<p><em>Click the image for full resolution.<\/em><\/p>\n<p>If true customization is required, the \u2018Custom Content\u2019 tab allows for mapping of items such as list file entries, or the Regular Expression tab allows for the use of logical operators.<\/p>\n<p>A best practice with regards to your Denylists selection may include Credit Card Numbers (CCN), Social Security Numbers (SSN), or even Personal Identifiable Information (PII).\u00a0 Under the Sample Data section, sample entries or files can be found at the site: DLPTest.com (<a href=\"https:\/\/dlptest.endpointprotector.com\/\" target=\"_blank\" rel=\"noopener\">https:\/\/dlptest.endpointprotector.com<\/a>).<\/p>\n<p>At this point, you can scroll to the bottom of the Policy edit page and choose to Save again &#8211; do this for each \u201cReport only\u201d policy created.<\/p>\n<h2>Predefined Policies vs. Custom Content<\/h2>\n<p>Using Endpoint Protector\u2019s \u2018Predefined Policy\u2019 option lets you focus attention on specific file types or data tied to particular regulatory items (such as HIPAA, PII, PCI-DSS, etc.). Depending on the Operating System in your environment, policies can be built for each of your Windows, macOS, and\/or Linux systems.<\/p>\n<p>If there is a need to look at specific items such as list files, \u2018Custom Content\u2019 can be entered or imported.\u00a0 Once the \u2018Custom Content\u2019 is added, this can be linked to a policy under the \u2018Custom Content\u2019 tab within the relevant entry.<\/p>\n<p>After a policy is created, it needs to be assigned to a target.\u00a0 The target can be either Departments, Groups, Computers, and\/or Users.\u00a0 To see the assigned targets of a Content Aware Protection policy, select the policy within the Content Aware Policy module of <a href=\"https:\/\/www.endpointprotector.com\/solutions\/data-loss-prevention\" target=\"_blank\" rel=\"noopener\">Endpoint Protector<\/a> and scroll to the bottom of the page.\u00a0 Should there be a need to make an edit, be sure to click the \u2018Save\u2019 button found just below the section to define the policy&#8217;s target.<\/p>\n<h2>Transition your CAP reports to a Blocking Policy<\/h2>\n<p>After reviewing your CAP report and understanding the types of data being moved from employee endpoints, you\u2019ll be ready to apply a blocking policy.<\/p>\n<p>Begin by cloning your\u00a0 \u201cReport only\u201d policy(s). Locate each \u201cReport only\u201d policy under Content Aware Protection &gt; \u2018Content Aware Policies,\u2019 and choose the \u2018Duplicate\u2019 icon found on the right-hand side of the policy.\u00a0 The second icon is seen in the three displayed icons column, which appears upon policy selection.<\/p>\n<p>After duplicating and creating each of the policies intended for Blocking, choose to edit these policies by using the \u2018Edit\u2019 icon found just above the \u2018Duplicate\u2019 icon.\u00a0 Modify the \u2018Policy Action:\u2019 selection to the desired Blocking method within each policy.\u00a0 Keep in mind that \u201cBlock and Remediate\u201d requires a Premium License package.\u00a0 Scroll to the bottom of each Policy page and verify all intended Policy Entities are selected, then click the Save button.\u00a0 After reviewing each new \u201cBlocking\u201d Policy, toggle the \u201cReport only\u201d policies to OFF.<\/p>\n<h2>Need help?<\/h2>\n<p>If you\u2019d like further information and guidance on setting up Content Aware Protection (or enabling it on your account), please reach out to your Customer Success Manager or contact our support team here <a href=\"https:\/\/support.endpointprotector.com\/hc\/en-us\/requests\/new\" target=\"_blank\" rel=\"noopener\">https:\/\/support.endpointprotector.com\/hc\/en-us\/requests\/new<\/a>.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>TL;DR Content Aware Protection allows Administrators to set up and enforce strong content filtering policies for selected users, computers, groups, or departments and take control over the risks posed by accidental or intentional file transfers of sensitive company data. Controls can be placed around predefined data (for example, PII, PHI, email addresses, passport numbers, credit &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/getting-started-with-content-aware-protection\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Getting Started with Content Aware Protection&#8221;<\/span><\/a><\/p>\n","protected":false},"author":8,"featured_media":5290,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2,1],"tags":[],"class_list":["post-5202","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-content-aware-protection","category-data-loss-prevention","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/5202","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=5202"}],"version-history":[{"count":13,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/5202\/revisions"}],"predecessor-version":[{"id":5291,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/5202\/revisions\/5291"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/5290"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=5202"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=5202"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=5202"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}