Secure Access Service Edge (SASE) provides an asset mapping feature that discovers and catalogs files on terminals, and intelligently generates detection rules to help you monitor and control outbound sensitive files. You can create asset mapping tasks to prevent data leaks through channels such as instant messaging and email.
Prerequisites
-
You have purchased the data loss prevention edition of SASE for Internet Access. For more information, see Billing overview and Get started with SASE.
-
Employee and department information is added. For more information, see Connect an LDAP IdP and Manage user groups.
-
The SASE client on your terminals is version 4.3.1 or later.
Step 1: Configure an asset mapping task
Create an asset mapping task to scan files on your terminals. SASE scans files based on the task configuration. Two task types are available:
-
Scheduled asset mapping task: Scans terminals on a recurring basis.
-
Immediate asset mapping task: Runs a one-time scan. This task is valid for 72 hours. If an employee does not log on to the SASE client within this period, their terminal is not scanned.
Immediate mapping task
-
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
On the Asset Map page, click Start Asset Mapping.
-
In the Start Asset Mapping panel, configure the following parameters and click OK.
Parameter
Description
Task Name
Enter a name for the immediate asset mapping task.
Report by Sensitivity Level
The sensitivity level threshold for reported files. The task classifies files based on identification rules and reports only those that match the specified level.
Scan Mode
Select a scan mode.
-
Quick Scan: Scans critical system paths, including services, drivers, startup items, running processes, and the Downloads, Desktop, and Documents directories.
-
Custom Scan: Scans the paths that you specify. You can add multiple paths.
-
Instructions:
1. File paths are supported.
2. Folder paths are supported.
3. System drive letters are supported.
4. Windows environment variables are supported.
-
Examples:
1. To scan a specific file: C:\scan_dir\scan_file.exe
2. To scan all files in a folder: C:\scan_dir
3. To scan all files on a drive: C:\
4. To scan all files in the APPDATA folder: %APPDATA%
-
-
Full Disk Scan: Scans all files on the disk.
-
Excluded Scan Path: Specify paths to exclude from the scan.
Perf Preference
The resource consumption level for the task. Three modes are available:
-
Experience First: Minimizes resource consumption for a smooth user experience. In extreme cases, the scan may be paused or canceled.
-
Balanced Mode: Balances resource allocation between user tasks and security scanning without significantly impacting user experience.
-
Security First: Prioritizes completing the scan to ensure security. This mode may consume more system resources.
Applicable User
Specify the users that the task applies to.
-
All Users: Scans all users who have the SASE client installed on their terminals.
-
Certain Users: Scans only the user groups that you select.
Exception User
Specify users to exclude from the scan. You can enter multiple usernames, separated by commas (,).
-
Scheduled mapping task
-
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
On the Asset Map page, click the Asset Mapping Tasks tab.
-
On the Asset Mapping Tasks page, click Create Asset Mapping Task.
-
In the Create Scheduled Asset Mapping Task panel, configure the following parameters and click OK.
Parameter
Description
Task Name
Enter a name for the scheduled task.
Priority
The priority of the scheduled task. Valid values: 1 to 100. A smaller value indicates a higher priority.
Report by Sensitivity Level
Specify the sensitivity level for the files to be reported. The task classifies files based on identification rules and reports only the files that match the specified sensitivity level. For more information about identification rules, see Configure identification rules for files transferred outbound.
Status
Enable or disable the scheduled task.
Scan Mode
Select a scan mode.
-
Quick Scan: Scans critical system paths, including services, drivers, startup items, running processes, and the Downloads, Desktop, and Documents directories.
-
Custom Scan: Scans the paths that you specify. You can add multiple paths.
-
Input Guide:
1. File paths are supported.
2. Folder paths are supported.
3. System drive letters are supported.
4. Windows environment variables are supported.
-
Example:
1. To scan a specific file: C:\scan_dir\scan_file.exe
2. To scan all files in a folder: C:\scan_dir
3. To scan all files on a drive: C:\
4. To scan all files in the APPDATA folder: %APPDATA%
-
-
Full Disk Scan: Scans all files on the disk.
-
Excluded Scan Path: Specify paths to exclude from the scan.
Frequency
Set the frequency for the scheduled scan.
Perf Preference
The resource consumption level for the task. Three modes are available:
-
Experience First: Minimizes resource consumption for a smooth user experience. In extreme cases, the scan may be paused or canceled.
-
Balanced Mode: Balances resource allocation between user tasks and security scanning without significantly impacting user experience.
-
Security First: Prioritizes completing the scan to ensure security. This mode may consume more system resources.
Applicable User
Specify the users that the task applies to.
-
All Users: Scans all users who have the SASE client installed on their terminals.
-
Certain Users: Scans only the user groups that you select.
Exception User
Specify users to exclude from the scan. You can enter multiple usernames, separated by commas (,).
-
Step 2: View asset mapping tasks
-
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
On the Asset Map page, click the Task Management tab.
-
On the Task Management page, view the immediate and scheduled asset mapping tasks that you have created.
-
You can filter tasks by criteria such as Scan Mode, Perf Preference Mode, and Task Status.
-
In the Actions column, click Cancel Task to cancel a running task.
-
Step 3: View reported files
After a mapping task completes, files that match the specified sensitivity level are reported. You can view the details of these files.
-
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
On the Asset Map page, view the reported file information.
-
You can filter the data by criteria such as time range, sensitivity level, file name, username, department, device name, device IP address, and device MAC address.
-
In the Actions column, click Preview to view the file's content.
-
Other operations
Intelligently generate rule
SASE selects the most relevant files reported by asset mapping tasks and uses a foundation model to learn from them. This generates new identification rules that are added to the intelligent recommendation library. You can use these rules to configure data classification policies. For more information, see Configure identification rules for files transferred outbound.
When you use the foundation model-based intelligent learning feature for the first time, SASE provides three free learning tasks. After you use them, you receive one additional free task each month.
-
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, choose .
-
On the Asset Map page, click Intelligently Generate Rule.
-
In the Intelligently Generate Rule panel, click Start New Learning Task. Configure the parameters as described in the following table, and then click Start.
Parameter
Description
Files for Learning
The number of files to use for learning. At least 5,000 files are required to generate accurate rules.
Detected At
The time range during which files were detected. The foundation model learns from files reported within this period.
File Size
The minimum file size for learning. You can filter for files larger than 10 KB.
File Format
The file formats for learning. Currently, only office documents are supported, including .ppt, .pptx, .pptm, .keynote, .key, .pages, .page, .dps, .xls, .xlsx, .xlsm, .xlam, .xlsb, .csv, .numbers, .lbx, .et, .doc, .docx, .docm, .dotm, .wps, .pdf, and .ofd.