Data Pattern
Select and define the data pattern match
criteria.
Predefined ML-based data patterns support only
the Any occurrence
condition with either High
or Lowconfidence. You can't
configure any other traffic match criteria other
than the confidence level for Predefined ML-based
data patterns.
If you enabled Local
Detection, Enterprise DLP displays
the supported regex data patterns only.
Occurrence Condition—Select
when the Security policy rule action triggers based
on the number of matched traffic instances Enterprise DLP detects.
Any—Triggers the Security policy rule
action if Enterprise DLP detects at least
one instance of matched traffic.
Less than or equal to—Triggers the
Security policy rule action if the number of
matched traffic instances Enterprise DLP
detects is at or below the specified
Count.
More than or equal to—Triggers the
Security policy rule action if the number of
matched traffic instances Enterprise DLP
detects meets or exceeds the specified
Count.
Between (inclusive)—Triggers the Security
policy rule action if the number of matched
traffic instances Enterprise DLP detects
falls within the specified
Count range.
Count—Specify the number of
instances of matched traffic required to trigger a
Security policy rule action. Range is
1 -
500.
The minimum supported value is 1 because a value of 0
would generate DLP incidents on forwarded traffic
that doesn't match any sensitive data patterns.
For example, to match sensitive data that appears
three or more times in a file, select
More than or equal to as
the Occurrence Condition and
specify 3 as the
Threshold.
Confidence—Specify the
confidence
level required for a Security policy rule
action to be taken (
High or
Low).
Unique Occurrences—Check (enable) to detect
only unique instances of traffic matches. Only
unique occurrences of traffic matches are counted
toward the specified
Count.
This setting is disabled by default. Keep
Unique Occurrences disabled
if you want all instances of traffic matches to
count toward the specified
Count.
Data Dictionary
Select and define the data dictionary match
criteria.
Occurrence Condition—Select
when the Security policy rule action triggers based
on the number of matched traffic instances Enterprise DLP detects.
Any—Triggers the Security policy rule
action if Enterprise DLP detects at least
one instance of matched traffic.
Less than or equal to—Triggers the
Security policy rule action if the number of
matched traffic instances Enterprise DLP
detects is at or below the specified
Count.
More than or equal to—Triggers the
Security policy rule action if the number of
matched traffic instances Enterprise DLP
detects meets or exceeds the specified
Count.
Between (inclusive)—Triggers the Security
policy rule action if the number of matched
traffic instances Enterprise DLP detects
falls within the specified
Count range.
Count—Specify the number of
instances of matched traffic required to trigger a
Security policy rule action. Range is
1 -
500.
The minimum supported value is 1 because a value of 0
would generate DLP incidents on forwarded traffic
that doesn't match any sensitive data patterns.
For example, to match sensitive data that appears
three or more times in a file, select
More than or equal to as
the Occurrence Condition and
specify 3 as the
Threshold.
Confidence—Specify the
confidence
level required for a Security policy rule
action to be taken (
High or
Low).
Unique Occurrences—Check (enable) to detect
only unique instances of traffic matches. Only
unique occurrences of traffic matches are counted
toward the specified
Count.
This setting is disabled by default. Keep
Unique Occurrences disabled
if you want all instances of traffic matches to
count toward the specified
Count.
Custom Document Types
Select and define the custom document type match
criteria.
Prisma Browser supports custom document types for cloud
detections only. You can't add a custom document type to a
data profile with Local Detection
enabled.
EDM
Select and define the EDM match criteria.
Prisma Browser supports custom document types for cloud
detections only. You can't add a custom document type to a
data profile with Local Detection
enabled.
EDM Dataset—Select an EDM data
set uploaded to the DLP cloud service.
Occurrence Condition—Specify
the occurrences condition required to trigger a
Security policy rule action.
Count—Specify the number of
instances of matched traffic required to trigger a
Security policy rule action. Range is
1 -
500.
- Configure EDM data set Primary
Fields values to specify whether a
Security policy rule action is taken if Any
(OR) or All (AND)
primary fields are matched and if Any
(OR) or All (AND)
secondary fields are matched.
(Any(OR) only) Enter the
Count to specify the number
of instances of matched traffic required to trigger
a Security policy rule action. Range is
1 -
500.
When you select Any (OR),
the maximum Count setting
is one less than the total number of fields
included in the Primary
Field or Secondary
Field.
Select the Primary
Fields values.
The list of
available values is populated from the selected EDM data
set. Select at least one primary field value.You’re
required to add at least one column where the column
values occurs up to 12 times in the selected EDM
data set for the Primary
Field. For example, if the EDM data
set contains columns for first name, last name,
social security number, and credit card number, add
social security number and credit card in the
primary field.
Data Profiles
Select to add a granular or nested data profile to
enhance your Enterprise DLP detection capabilities by
enabling you to apply differentiated inline content
inspection requirements and response actions within the same
Security policy rule.
For example, you can use a granular profile to block
high-risk data patterns while alerting on lower-risk ones,
set varying log severities for different data profiles, and
selecting specific file types for each data profile included
the granular data profile. Granular profiles simplify policy
rulebase management by consolidating multiple rules into a
single, more flexible policy. This allows your security
administrators to streamline Security policy rulebase
administration. It reduces false positive detections and
achieves a more nuanced approach to data protection that
aligns closely with your organization's risk management
strategy while maintaining a lean and efficient policy
rulebase.
(Enterprise DLP Plugin
5.0 and earlier releases) Granular profiles are
backwards compatible. This means that if you can configure a
granular profile on Strata Cloud Manager, Enterprise DLP can successfully synchronize the granular data profile
and make it available for use on Panorama and NGFW running PAN-OS 11.1 or
earlier releases and Enterprise DLP plugin 5.0 and
earlier releases.
Search for and select one or more compatible
predefined or
custom data profiles and click
Apply
to add them.
Enterprise DLP does not support adding a
granular or nested profile to another granular or nested
profile.
If you enabled Local Detection, you
can only add other data profiles with Local
Detection enabled.
Group
Select to nest and group additional match criteria
so you can more accurately define your compliance rules.
When you click add a new Group, the
new match criteria group is nested under the most recently
added match criteria. You can’t nest a new match criteria
group between existing match criteria. If you add multiple
match criteria, you must remove the match criteria that
follow the match criteria that you want to add.
For example, you added
EDM_Dataset1,
Data_Pattern2, and
EDM_Dataset3 to the Primary
Rule. If you wanted to added nested match criteria to
Data_Pattern2, you must
first remove EDM_Dataset3 from
the Primary Rule.
You can select the same match criteria or different match
criteria to more accurately define your compliance rules.
Enterprise DLP supports up to three level of
additional groups for each match criteria.
Nested match criteria support the AND,
OR, and
NOT operators. Refer to the
descriptions above to configure the nested match
criteria.