With the changing security and compliance requirements of your organization, you can edit the policies that you have created in IBM® Guardium® Exposure Manager to scale and adapt, as required.
Before you begin
You cannot edit the Default workload policy and a Default workforce policy that are automatically created during the onboarding process of IBM Guardium Exposure Manager.
About this task
Use the following steps to edit a policy in IBM Guardium Exposure Manager.
Procedure
-
From the main menu, click Policies.
-
In the Policies page, click the policy that you want to edit.
-
In the policy details page, click Edit Policy.
-
In the Define rule tab of the policy details page, configure the following rule parameters, and then click Save.
- Under the Allow section, for a workload policy, you can see the following:
- The rules for the data classification category that are allowed in the projects assigned to the policy.
- The type of sensitivity levels that are associated with the rule.
- Under the Allow section, for a workforce policy, you can see the following:
- Content shared through the trusted destinations type that are allowed in the cohorts assigned to the policy.
- The rules for the data classification category that are allowed in the cohorts assigned to the policy.
- Under the Otherwise section, for a workload policy, you can see the following:
- The category of issue, High severity, Medium severity, or Low severity, that is reported if the rule set for the policy is violated.
- The notification mechanism, Slack message, Email, SIEM, or all, for violating the rule set for the policy.
- Under the Otherwise section, for a workforce policy, you can see the following:
- The category of issue, High severity, Medium severity, or Low severity, that is reported if the rule set for the policy is violated.
- The action mechanism, either warning or justification for violating the rule set for the policy.
- The alert mechanism, either Slack message, Email, or SIEM for violating the rule set for the policy.
Note:
- After completing the configuration of a rule, you can click Add new rule to configure another rule.
- You can toggle the rule as Active or Inactive. By default, the rule is set as Active.
- You can click the Delete icon to delete a rule.
Results
You have successfully edited a policy in IBM Guardium Exposure Manager to manage enterprise data security and prevent data leak.