RSA Data Loss Prevention Policy and Classification
Duration: 25-30hrs
Course Content:
Search and Categorization Overview
- Review search methodologies
- Define how to measure accuracy
- Define precision and recall
- Compare ranks and weights
- Review search features related to words, phrases, patterns, and entities
- Define how proximity is used
- Build an effective rule set
- Define what regular expressions are and how they are used
- List tools available to create and test regular expressions
- Review detailed syntax for creating regular expressions
- Analyze sample regular expressions
Building Content Blades
- Create regular expressions to detect sensitive content
- Identify the types of content blades
- Review detection rules
- Compare describing and fingerprinting content
- Build described content blades
- Compare and analyze file and database fingerprinting in detail
- Review fingerprinting frequently asked questions
- Build fingerprinted content blades
Content Blade Best Practices
- Review described content blade best practices
- Review fingerprinted content blade best practices
Building Policies
- Define what policies are and how they are used
- Review common policy features
- Explain the relationship between policies and content blades
- Use policies to identify sensitive content
- Review DLP Network policy features
- Review DLP Endpoint policy features
- Review DLP Datacenter policy features
- Configure policy-level remediation
- Create and tune policies to increase recall and precision
- Navigate the policy template library
Regulatory Compliance
- Review existing regulatory compliance policies available in RSA DLP
- Analyze FERC-related policies
- Analyze HIPAA-related policies
Incidents and Events
- Define what incidents and events are
- View incident lists
- Customize searches for incidents and events
- Review available incident actions
- Analyze incident and event details
Methodologies
- Review best practices for building content blades
- Research corporate policies
- Gather test documents
- Identify linguistic evidence
- Build for recall
- Tune for precision
- Test for accuracy
- Document detection rules