You can also use URL categories to phase-in
decryption, and to exclude URL categories that might contain
sensitive or personal information from decryption (like
financial-services and health-and-medicine). Plan to
decrypt the riskiest traffic first (URL categories most likely
to harbor malicious traffic, such as high-risk) and then decrypt
more as you gain experience. Alternatively, decrypt the URL
categories that don’t affect your business first (if something
goes wrong, it won’t affect business), for example, news feeds.
In both cases, decrypt a few URL categories, listen to user
feedback, run reports to ensure that decryption is working as
expected, and then gradually decrypt a few more URL categories,
and so on. Plan to make decryption exclusions
for sites you can't decrypt either for technical reasons or
because you choose not to decrypt them.
Decrypting traffic based on URL categories is a best
practice for both URL Filtering and Decryption.
|