简介
本文档介绍在思科邮件安全设备(ESA)的传出邮件策略中启用DLP后,如何测试健康保险流通与责任法案(HIPAA)数据丢失保护(DLP)。
触发DLP违规以测试HIPAA策略
本文提供一些真实内容,这些内容已经过修改,目的是保护人员,以针对ESA上的DLP策略进行测试。此信息旨在触发HIPAA和经济与临床健康信息技术(HITECH) DLP策略,并触发其他DLP策略,如社会保险号(SSN)、CA AB-1298、CA SB-1386等。当您通过ESA发送测试电子邮件或使用跟踪工具时,请使用这些信息。
注意:在粗体显示的输出中,必须使用有效或常见误用的SSN。
注意:对于HIPAA和HITECH DLP策略,请确保您已按照建议配置了自定义标识号。患者标识号(建议定制)或美国国家提供商标识符或美国社会保障号与医疗保健词典。必须对此进行配置才能正确触发。
Procedure Notes
Progress Notes
Archie M Johnson Tue Jun 30, 2009 10:31 AM Pended
June 30, 2009
Patient Name: Gina, Lucas DOB: 01/23/1945
Telephone #: (559) 221-2345
SS#: [[[PLACE SSN HERE]]]
--------------------------------------------------------------------------------
Insurance: UHC
How was the patient referred to the office: *** ({:20})
Is a family member currently being seen by the requested physician? {YES/NO:63}
If yes, what is the family members name : ***
Previous PCP / Medical Group? ***
Physician Requested: Dr. ***
REASON:
1) Get established, no current problems: {YES/NO:63}
2) Chronic Issues: {YES/NO:63}
3) Specific Problems: {YES/NO:63}
Description of specific problem and/or chronic conditions:
{OPMED SYMPTOMS:11123} the problem started {1-10:5044} {Time Units:10300}.
Any Medications that may need a refill? {YES/NO:63}
Current medications: ***
--------------------------------------------------------------------------------
Archie M Johnson
Community Health Program Assistant Chief
Family Practice & Community Medicine
(559) 221-1234
Lucas Gina Wed Jul 8, 2009 10:37 AM Pended
ELECTIVE NEUROLOGICAL SURGERY
HISTORY & PHYSICAL
CHIEF COMPLAINT: No chief complaint on file.
HISTORY OF PRESENT ILLNESS: Mary A Xxtestfbonilla is a ***
Past Medical History
Diagnosis Date
• Other Deficiency of Cell-Mediated Immunity
Def of cell-med immunity
• Erythema Multiforme
• Allergic Rhinitis, Cause Unspecified
Allergic rhinitis
• Unspecified Osteoporosis 12/8/2005
DEXA scan - 2003
• Esophageal Reflux 12/8/2005
priolosec, protonix didn't work, lost weight
• Primary Hypercoagulable State
MUTATION FACTOR V LEIDEN
• Unspecified Glaucoma 1/06
• OPIOID PAIN MANAGEMENT 1/24/2007
Patient is on opioid contract - see letter 1/24/2007
• Chickenpox with Other Specified Complications 2002
验证
根据您为DLP策略设置的邮件操作,您的结果会有所不同。通过GUI中的查看功能配置和确认设备的操作:邮件策略(Mail Policies) > DLP策略自定义(DLP Policy Customizations) >邮件操作(Message Actions)。
在本示例中,Default Action被设置为将DLP违规隔离到策略隔离区,并且还会修改带有前缀“[DLP VIOLATION]”的邮件主题行。
当您通过发送以前的内容作为测试电子邮件时,mail_logs应显示与此类似的内容:
Wed Jul 30 11:07:14 2014 Info: New SMTP ICID 656 interface Management (172.16.6.165)
address 172.16.6.1 reverse dns host unknown verified no
Wed Jul 30 11:07:14 2014 Info: ICID 656 RELAY SG RELAY_SG match 172.16.6.1 SBRS
not enabled
Wed Jul 30 11:07:14 2014 Info: Start MID 212 ICID 656
Wed Jul 30 11:07:14 2014 Info: MID 212 ICID 656 From: <my_user@gmail.com>
Wed Jul 30 11:07:14 2014 Info: MID 212 ICID 656 RID 0 To: <test_person@cisco.com>
Wed Jul 30 11:07:14 2014 Info: MID 212 Message-ID
'<A85EA7D1-D02B-468D-9819-692D552A7571@gmail.com>'
Wed Jul 30 11:07:14 2014 Info: MID 212 Subject 'My DLP test'
Wed Jul 30 11:07:14 2014 Info: MID 212 ready 2398 bytes from <my_user@gmail.com>
Wed Jul 30 11:07:14 2014 Info: MID 212 matched all recipients for per-recipient
policy DEFAULT in the outbound table
Wed Jul 30 11:07:16 2014 Info: MID 212 interim verdict using engine: CASE spam
negative
Wed Jul 30 11:07:16 2014 Info: MID 212 using engine: CASE spam negative
Wed Jul 30 11:07:16 2014 Info: MID 212 interim AV verdict using Sophos CLEAN
Wed Jul 30 11:07:16 2014 Info: MID 212 antivirus negative
Wed Jul 30 11:07:16 2014 Info: MID 212 Outbreak Filters: verdict negative
Wed Jul 30 11:07:16 2014 Info: MID 212 DLP violation
Wed Jul 30 11:07:16 2014 Info: MID 212 quarantined to "Policy" (DLP violation)
Wed Jul 30 11:08:16 2014 Info: ICID 656 close
使用跟踪工具时,如果使用邮件正文中的以前内容,则会看到类似以下图像列出的结果:
故障排除
确保已从GUI中的邮件策略(Mail Policies) > DLP策略管理器(DLP Policy Manager) >添加DLP策略……中选择所需的DLP策略。
检查DLP策略(如已添加),并确保已指定内容匹配分类器且正则表达式模式有效。另请确保已配置AND match with related words or phrases部分。分类器是DLP引擎的检测组件。它们可以组合使用或单独使用,以识别敏感内容。
注意:预定义的分类器不可编辑。
如果没有看到基于内容的DLP触发器,请同时查看邮件策略>传出邮件策略> DLP,并确保您启用了所需的DLP策略。
相关信息