This guide will walk you through the process of creating a policy to prevent inbound risks in your cloud environment.
STEP ONE:
Sign into your Cloud Access Monitor Instance.
Select the "x Enabled" policies button to the right of the desired Cloud Environment.
Enter your Email you wish to receive alerts to.
Select the "Add Policy" Button on the bottom right of the screen.
The Add Policy window will appear.
Give your policy a Name.
Select the Source(s) you would like to enforce the policy on.
Select File type(s), blank (all) is recommended.
Select File Size, blank (all) is recommended.
Under the Threats Column select the risk(s) that you wish to apply the policy to.
In the Sharing Column, select the From Outside Domain Checkbox.
Once you have setup your custom policy select the Apply button on the bottom left.
At this point you may choose if you would like any Automatic Remediation to take place. Each source has its own remediation options.
Drive:
- Delete: Will delete the file from the drive.
- Quarantine: Will place the file into a folder in the administrative g-drive named CAM_Quarantine
- Revoke Sharing From Outside Domain: Will remove the share if it is coming from an outside domain.
- Warn User: Send the user who triggered the violation an email warning them of their behavior.
Email:
- Delete: This will delete the e-mail as soon as it is found to contain risk.
- Quarantine: Will move the e-mail into the users trash folder
- Warn User: Send the user who triggered the violation an email warning them of their behavior.
- Delete: This will delete the e-mail as soon as it is found to contain risk.
- Warn User: Send the user who triggered the violation an email warning them of their behavior.
Once you have chosen your remediation options (if any), the next step is to choose when remediation options will occur. Options include...
Immediately: The action will occur as soon as the policy is violated.
One Day: In 24 Hours the remediation will occur.
Three Days: In three days the remediation will occur.
One Week: In one week the remediation will occur.
Two Weeks: In two weeks the remediation will occur
Choose who will be notified if a remediation does occur.
Notify User: Notify the user that caused the policy violation to occur.
Notify Admin: Notify the Cloud Access Monitor Admin of the infraction.
Select the save button at the bottom right of the window.
Enable / Disable: To enable or disable a policy, simply click the enable button found on the policy window.
Edit: To edit an existing policy click the edit pencil on the right side of the policy window.
Delete: To delete a policy, simply click the trash can icon on the right side of the policy window.
Comments
0 comments
Please sign in to leave a comment.