You can create policies in IBM® Guardium® Exposure Manager to enforce rules and conditions on logical groups of data stores or devices to manage enterprise data security, prevent data leak, and adopt AI safely.
Before you begin
Before you start creating a policy in IBM Guardium Exposure Manager, ensure that you have completed the process of onboarding.
About this task
Note: A Default workload policy and a Default workforce policy are automatically created during the onboarding process.
Use the following steps to create a policy in IBM Guardium Exposure Manager.
Procedure
-
From the main menu, click Policies.
-
In the Policies page, click Create policy.
-
In the Define policy step of the Create policy wizard, do the following tasks, and then click Next.
-
Select the category of scope for the policy as either Workforce or Workload.
-
Enter the name of the policy.
-
(Optional) Enter the description of the policy.
-
In the Create rules step of the Create policy wizard, click Add new rule, configure the following rule parameters, and then click Next:
- Under the Allow section, for a workload policy, you can see the following:
- The rules for the data classification category that are allowed in the projects assigned to the policy.
- The type of sensitivity levels that are associated with the rule.
- Under the Allow section, for a workforce policy, you can see the following:
- Content shared through the trusted destinations type that are allowed in the cohorts assigned to the policy.
- The rules for the data classification category that are allowed in the cohorts assigned to the policy.
- Under the Otherwise section, for a workload policy, you can see the following:
- The category of issue, High severity, Medium severity, or Low severity, that is reported if the rule set for the policy is violated.
- The notification mechanism, Slack message, Email, SIEM, or all, for violating the rule set for the policy.
- Under the Otherwise section, for a workforce policy, you can see the following:
- The category of issue, High severity, Medium severity, or Low severity, that is reported if the rule set for the policy is violated.
- The action mechanism, either warning or justification for violating the rule set for the policy.
- The alert mechanism, either Slack message, Email, or SIEM for violating the rule set for the policy.
Note:
- After completing the configuration of a rule, you can click Add new rule to configure another rule.
- You can toggle the rule as Active or Inactive. By default, the rule is set as Active.
- You can click the Delete icon to delete a rule.
-
In the Assign assets step of the Create policy wizard, select the cohorts or projects to which you want to apply the policy, and then click Create
Results
You have successfully created a policy in IBM Guardium Exposure Manager to securely adopt and manage AI data security.