Cloud Email and Collaboration
Protection also provides Keyword Extraction as
a simplified keyword-based way that allows you to quickly identify sensitive information
contained in Box files and create rules to limit or prevent the transmission of the
data.
Configuring keyword extraction
Procedure
- Select Keyword Extraction.
- Select Enable Keyword Extraction.
- Configure Rules settings.
-
In File Format, select one or multiple file formats to apply the criterion.
Note
Cloud Email and Collaboration Protection scans the specified keywords in text and PDF files, and in the header, footer, and properties of Microsoft Word, Excel, and PowerPoint files. -
Select Contain Type to indicate the condition for the criterion.
-
Specify a keyword to scan in the Keywords text box, and click Add.The keyword appears in the blank area.Cloud Email and Collaboration Protection scans files for the specified keyword and triggers a keyword extraction rule when the content matches the keyword, including content with the following separators to the left or right of the content: "\t", "\n", "\r", ",", ".", and spaces.Take keyword Internal Use Only as an example. Cloud Email and Collaboration Protection triggers the keyword extraction rule when the content includes Internal Use Only. while does not when the content includes aaINTERNAL USE ONLYbb.
-
Optionally repeat the above step to add more keywords for the selected file format(s).
Note
Optionally click Import to import existing keywords in batches from a text file. Make sure that each line in the file contains one keyword.Optionally select one or multiple keywords and click Remove Selected to delete the keywords. -
Click Add to Rule List.
Note
The setting appears in the Rule List table, each file format per line.You can add keywords for a single file format in multiple times, and all these keywords will be combined into one rule. -
Optionally repeat steps a through e if you need to set another condition for a file format.
Note
Cloud Email and Collaboration Protection separates the Contain and Not Contain conditions in two rules for each file format. It enables you to set actions for each condition rule respectively. -
Optionally click Export to export all the configured keywords.
-
Select an action for each rule from the drop-down list.In the case of two separate rules for a file format, Cloud Email and Collaboration Protection takes the action with the higher priority to a file when keyword(s) in a rule hit the corresponding criterion. The actions come with the following priorities from high to low: Delete, Quarantine, Pass.OptionDescriptionDeleteCloud Email and Collaboration Protection deletes the file and replaces it with a placeholder using the original file name and
.txt
.QuarantineCloud Email and Collaboration Protection moves the file to a restricted access folder, removing it as a security risk to protected Box.PassCloud Email and Collaboration Protection records the detection in a log and delivers the file unchanged. -
Optionally click the trash icon to delete the corresponding rule.
-
- Configure Action settings.
Option Description NotifyCloud Email and Collaboration Protection sends a notification email message to the administrator or user according to the Notification settings.Do not notifyCloud Email and Collaboration Protection only takes the configured action on the file and does not send out any notification email message.Show Advanced OptionsSpecify text to replace the original file content when a file is quarantined or deleted. - Configure Notification settings.
Option Description Notify administratorSpecify message details to notify administrators that Cloud Email and Collaboration Protection detected a security risk and took action on an email message, attachment, or file.Set the notification threshold which limits the number of notification messages to send. Threshold settings include:-
Send consolidated notifications periodically: Cloud Email and Collaboration Protection sends an email message that consolidates all the notifications for a period of time. Specify the period of time by typing a number in the box and selecting hour(s) or day(s).
- Send consolidated notifications by occurrences: Cloud Email and Collaboration Protection sends an email message that consolidates notifications for a set number of filtering actions. Specify the number of data loss occurrences by typing a number in the box.
-
Send individual notifications: Cloud Email and Collaboration Protection sends an email message notification every time Cloud Email and Collaboration Protection performs a filtering action.
Notify UserBox: Specify message details that notify the user who uploaded a file that Cloud Email and Collaboration Protection detected a security risk and took action on their file.Optionally select the Do not notify external user check box. This allows the administrator to choose not to notify an end user of policy violation details if the user violating the policy does not belong to your organization.Note
When specifying a notification message, include relevant tokens and edit the message content as desired. For details about tokens, see Token list. -