User Guide

17-24
AsyncOS 9.1.2 for Cisco Email Security Appliances User Guide
Chapter 17 Data Loss Prevention
RSA Enterprise Manager
About Deleting and Disabling Policies in Enterprise Manager Deployments, page 17-33
Lost Connectivity Between the Email Security Appliance and Enterprise Manager, page 17-33
Switching from Enterprise Manager to RSA Email DLP, page 17-33
How Enterprise Manager and the Email Security Appliance Work Together
When you enable RSA Enterprise Manager DLP on the Email Security appliance, the appliance sends
the configuration to Enterprise Manager, which automatically adds the Email Security appliance as a
partner device. The next time you open Enterprise Manager, the names and metadata of the outgoing mail
policies and message actions that you configured on the Email Security appliance appear in Enterprise
Manager, ready for you to use when configuring DLP policies. (Alternately, you can export existing DLP
policies from the Email Security appliance to Enterprise Manager.)
After you configure DLP policies on Enterprise Manager, Enterprise Manager sends the DLP policies to
the Email Security appliance. By default, all DLP policies pushed by Enterprise Manager are enabled on
all devices they’re pushed to, including Email Security appliances.
The Email Security appliance stores the DLP policies it receives from Enterprise Manager and uses them
to scan outgoing messages for violations, and take action on any violations found. The Email Security
appliance processes messages that are released for delivery, including encrypting the message if
applicable. The Email Security appliance sends information about violations to Enterprise Manager for
viewing and management.
Related Topics
How Data Loss Prevention Works, page 17-2
DLP Deployment Options, page 17-3
Enterprise Manager Documentation
For this deployment, you may need the following documentation from RSA Inc.:
Managing Partner Device DLP with Enterprise Manager (technical note). Instructions on setting up
Enterprise Manager and using it to manage the DLP features of partner devices, including Cisco
Email Security appliances.
RSA DLP Network 9.0 Deployment Guide. Instructions on deploying RSA DLP software on a
network.
RSA DLP Network 9.0 User Guide. Instructions for using the RSA DLP Network software, including
how to use Enterprise Manager to manage partner DLP devices such as the Cisco Email Security
appliance.
How to Set up Data Loss Prevention in Deployments with RSA Enterprise
Manager
Perform these steps in order: