Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revisionBoth sides next revision
piidiscovery [2018_04_05 15:55] – [Configuration] stevenpiidiscovery [2018_04_06 18:37] – v2.0 updates part 1 steven
Line 1: Line 1:
-# PII Discovery+# PII Scanning and Detection
 (available in v1803) (available in v1803)
  
 This page covers the identification and classification of PII (Personally Identifiable Information). This page covers the identification and classification of PII (Personally Identifiable Information).
  
-The Enterprise File Fabric's PII feature helps enterprise customers manage personal information by automatically detecting PII in documents and alerting the organisation’s information security specialists or other designated users to its presence.+The Enterprise File Fabric's PII Scanning and Detection feature helps enterprise customers manage personal information by automatically detecting PII in documents and alerting the organisation’s information security specialists or other designated users to its presence.
  
 [[https://www.youtube.com/watch?time_continue=7&v=zxpyY3Rw34c|{{ ::piidiscovery:piivideo.png?nolink&300 |}}]] [[https://www.youtube.com/watch?time_continue=7&v=zxpyY3Rw34c|{{ ::piidiscovery:piivideo.png?nolink&300 |}}]]
Line 14: Line 14:
 ### Scanning ### Scanning
  
-The PII Discovery feature works by scanning documents when they are added or updated. Documents are searched using a configurable set of rules, looking for personal information such as telephone numbers, email addresses and national identity numbers.+The PII Scanning and Detection feature works by scanning documents when they are added or updated. Documents are searched using a configurable set of rules, looking for personal information such as telephone numbers, email addresses and national identity numbers.
  
 {{ :piidiscovery:file-and-folders-pii.png?nolink&800 |}} {{ :piidiscovery:file-and-folders-pii.png?nolink&800 |}}
Line 20: Line 20:
 ### Tagging ### Tagging
  
-Files in which personal information is found are classified as PII with the types of PII data that they contain:+Files in which personal information is found are classified as PII with the types of PII data that they contain. Users with appropriate permissions can see the PII that has been found in a document on the “info” tab for that document:
  
 {{ :piidiscovery:tagging.png?nolink |}} {{ :piidiscovery:tagging.png?nolink |}}
Line 32: Line 32:
 {{ :piidiscovery:notify_admin_email.png?500&nolink |}} {{ :piidiscovery:notify_admin_email.png?500&nolink |}}
  
-The file owner, the user who uploaded the file, receives an email and a message:+The file owner, (the user who uploaded the file,receives an email and a message:
  
 {{ :piidiscovery:notify_owner_alert.png?nolink |}} {{ :piidiscovery:notify_owner_alert.png?nolink |}}
Line 44: Line 44:
 {{ :piidiscovery:searchpiicheckboxes.png?nolink |}} {{ :piidiscovery:searchpiicheckboxes.png?nolink |}}
  
-Look under the “info” tab for specific PII information a document contains: 
- 
-{{ :piidiscovery:infotab_piifound.png?nolink | 
-}} 
 ## Workflow ## Workflow
  
 ### Uploading ### Uploading
  
-When a file or object is uploaded, updated or synchronized the File Fabric recognizes it as containing new content; it is a candidate for being indexed and scanned.+When a file is uploaded, updated or synchronized the File Fabric recognizes it as containing new content; it is a candidate for being scanned for PII.
  
 To be scanned the file must be located on a storage provider that has content search enabled (this is set set when the provider is created). To be scanned the file must be located on a storage provider that has content search enabled (this is set set when the provider is created).
Line 72: Line 68:
 ### Tagging of PII Files ### Tagging of PII Files
  
-When PII is detected in a file, a tag is added to the file indicating the type of PII that was detected.  For example, if the File Fabric is configured to scan for US Social Security Numbers (SSNs) and one or more data values that match the US SSN detection rule are found when the file is scanned, then a tag with the value “US Social Security Number” will be added to the file metadata under the PII classification.+When PII is detected in a file, a tag is added to the file indicating the type of PII that was detected.  For example, if the File Fabric is configured to scan for US Social Security Numbers (SSNs) and one or more data values that match the US SSN detection rule are found when the file is scanned, then a tag with the value “US Social Security Number” will be added to the file'metadata under the PII classification.
  
 {{ :piidiscovery:tagging.png?nolink |}} {{ :piidiscovery:tagging.png?nolink |}}
- 
  
  
Line 81: Line 76:
  
 Administrators and users with PII permission are notified when a file that matches the PII rules has been detected. Administrators and users with PII permission are notified when a file that matches the PII rules has been detected.
- 
  
 Users with PII permission, including administrators, receive a notification by email: Users with PII permission, including administrators, receive a notification by email:
Line 88: Line 82:
 {{ :piidiscovery:notify_admin_email.png?500&nolink |}} {{ :piidiscovery:notify_admin_email.png?500&nolink |}}
  
-The file ownerthe user who uploaded the file, receives both an email and a message.+The file owner (the user who uploaded the file), receives both an email and a message.
  
 {{ :piidiscovery:notify_owner_email.png?500&nolink |}} {{ :piidiscovery:notify_owner_email.png?500&nolink |}}
Line 129: Line 123:
 ### File Information ### File Information
  
-Available to uIf a file contains PII, a “Show PII matches” button is displayed on the File Manager Info tab for the file. This is available to users with PII or administration permissions.+If a file contains PII, a “Show PII matches” button is displayed on the File Manager Info tab for the file. This is available to users with PII or administration permissions.
  
 {{ :piidiscovery:show_pii_matches_button.jpg?nolink |}} {{ :piidiscovery:show_pii_matches_button.jpg?nolink |}}
Line 159: Line 153:
  * Add Storage Providers with Content Search  * Add Storage Providers with Content Search
  * Give Users PII Authorization  * Give Users PII Authorization
- Edit the PII Detection Rules (optional)+ Configure PII Detection Rules (optional)
  * Change the Name of the PII Classification (optional)  * Change the Name of the PII Classification (optional)
  
 ### 1. Enabling the Content Search Engine ### 1. Enabling the Content Search Engine
  
-Content search must be enabled for PII scanning and detection to work. The content search engine scans documents for PII as they are uploaded or synchronized. The search engine is available only with the appliance and must be explicitly enabled.+Content search must be enabled for PII scanning and detection to work. The content search engine scans documents for PII as they are uploaded or synchronized. The search engine is available only with the Enterprise File Fabric appliance and must be explicitly enabled.
  
 Here is a link to instructions for configuring the content search engine:  [[cloudappliance/solr]] Here is a link to instructions for configuring the content search engine:  [[cloudappliance/solr]]
Line 170: Line 164:
 ### 2. Enabling PII Scanning and Detection in User Packages ### 2. Enabling PII Scanning and Detection in User Packages
  
-PII scanning and detection is only available to Teams (orgs.) that have been assigned a User Package in which the feature is enabled.  The appliance administrator (appladmin) can set this option for a Package by:+PII Scanning and Detection is only available to Organizations that have been assigned a User Package in which the feature is enabled.  The appliance administrator (appladmin) can set this option for a Package by:
  
   * choosing “User Packages” from the hamburger menu;   * choosing “User Packages” from the hamburger menu;
Line 182: Line 176:
 ### 3. Enable the Policy “PII Scanning & Detection” ### 3. Enable the Policy “PII Scanning & Detection”
  
-An administrator can enable this features under Policies > PII Scanning & Detection.+An administrator can enable this feature under Policies > PII Scanning & Detection.
  
 {{ :piidiscovery:org_policies_pii.png?nolink |}} {{ :piidiscovery:org_policies_pii.png?nolink |}}
Line 192: Line 186:
 {{ :piidiscovery:cos_info.png?600&nolink |}} {{ :piidiscovery:cos_info.png?600&nolink |}}
  
-Files that existed before are indexes during the initial provider synchronization. Subsequently files are indexed when created or updated, or if a provider cloud sync is executed.+Files that existed before the provider was added are indexed during the initial provider synchronization. Subsequently files are indexed when created or updated, or if a provider cloud sync is executed and new or updated files are discovered.
  
 Search cannot be enabled for an existing provider data source. To verify that content search is enabled for a provider, as an organizational administrator go to the Dashboard. Select the Setting gear icon to go to see the data source provider detail. The //Content index// for search setting must be set to //Yes//. Search cannot be enabled for an existing provider data source. To verify that content search is enabled for a provider, as an organizational administrator go to the Dashboard. Select the Setting gear icon to go to see the data source provider detail. The //Content index// for search setting must be set to //Yes//.
Line 214: Line 208:
 Another way to give a user PII authorization is to assign the Admin role.  Assigning the Admin role to a user gives several other administrative privileges and should not be done without a complete understanding of the implications. Another way to give a user PII authorization is to assign the Admin role.  Assigning the Admin role to a user gives several other administrative privileges and should not be done without a complete understanding of the implications.
  
-### 6. Editing the PII Detection Rules+### 6. Configuring PII Detection Rules
  
 A set of rules for detecting different kinds of PII is provided with the Enterprise File Fabric. These rules can be used as provided, or the administrator can remove or change rules to meet the organization’s specific requirements. A set of rules for detecting different kinds of PII is provided with the Enterprise File Fabric. These rules can be used as provided, or the administrator can remove or change rules to meet the organization’s specific requirements.