Managing policies
A policy is a set of rules and conditions that specifies what is allowed, monitored, warned about, or enforced within a system. With IBM® Guardium® Exposure Manager, you can create, edit, and apply policies to Projects (workload) and Cohorts (workforce). You can use the policies to prevent data leak and to control enterprise data security that is used across AI applications, databases, and endpoints.
The policies you create can enable you to manage the data exposure risk, secure AI data, and scale enterprise AI adoption safely.
The table in the Policies page lists the default policy that is automatically created during the onboarding process of IBM Guardium Exposure Manager and the other policies that you have created. The table provides the following details and insights about the policies.
- Policy name
- Name of the policy.
- Assigned to
- If a policy is assigned to a single project or cohort, you can see the name of the project or cohort in the Assigned to column. However, if a policy is assigned to multiple projects or cohorts, you can see the number of projects or cohorts assigned to the policy in the Assigned to column.
- Category
- The category of scope, that is associated with the policy. The category is either Workforce or Workload. Workload is also referred to as a project, and Workforce is also referred to as a cohort.
- Created by
- Name of the user who created the policy.
- Last updated
- The date and time at which the policy was last updated.
- Status
- The status of the policy, either Active or Inactive.
When you click any policy listed in the table of the Policies page, you can find additional information in the following tabs of the policy page.
- Rules
- The Rules tab displays the the following details about rule configurations.
- Under the Allow section, for a workload policy, you can see the following:
- The rules for the data classification category that are allowed in the projects assigned to the policy.
- The type of sensitivity levels that are associated with the rule.
- Under the Allow section, for a workforce policy, you can see the following:
- Content shared through the trusted destinations type that are allowed in the cohorts assigned to the policy.
- The rules for the data classification category that are allowed in the cohorts assigned to the policy.
- Under the Otherwise section, for a workload policy, you can see the following:
- The category of issue, High severity, Medium severity, or Low severity, that is reported if the rule set for the policy is violated.
- The notification mechanism, Slack message, Email, SIEM, or all, for violating the rule set for the policy.
- Under the Otherwise section, for a workforce policy, you can see the following:
- The category of issue, High severity, Medium severity, or Low severity, that is reported if the rule set for the policy is violated.
- The action mechanism, either warning or justification for violating the rule set for the policy.
- The alert mechanism, either Slack message, Email, or SIEM for violating the rule set for the policy.
- Under the Allow section, for a workload policy, you can see the following:
- Scopes
- The Scopes tab specifies the following things:
- Name of the project or cohort assigned to the policy.
- The number of data stores or devices that are associated with the project or cohort.
- The name of the owner of the project assigned to the policy.