Previous Topic: Intervention Setting

Next Topic: Intervention Setting: Block with Notification

Intervention Setting: Advise Encryption

Available for: Outgoing Emails, Data In Motion

Not available for: Incoming Emails, Web, Data At Rest. Files, webmails and STMP emails detected by the NBA; see the note below.

Important! Do not choose this intervention option for your NBA triggers. The NBA cannot send encryption warnings when it detects unencrypted files, webmails and SMTP emails. Consequently, such items are sent or copied without encryption.

Choose Advise Encryption to warn users whenever CA DLP detects an attempt to send an unencrypted email or copy an unencrypted file to a removable device such as a USB drive. You can specify a customized notification message for each control trigger.

Emails

For emails detected by a CA DLP endpoint agent, CA DLP displays a warning dialog to the email sender. The sender can choose one of the following:

Encrypt

CA DLP inserts an 'encryption request' x-header into the email. This x-header is subsequently detected by a third-party encryption provider, which in turn encrypts the email before it leaves your network.

Don't Encrypt

The email is sent unencrypted.

Cancel

The email is not sent.

For emails detected by a CA DLP email server agent:

Important! If server-side interactive warnings are enabled, make sure that the message to users in the warning email clearly explains the consequences of replying and not replying! In particular, note the different reply handling for the Advise Encryption and Enforce Encryption options.

Data In Motion

When the warning displays, the user copying the file can choose one of the following:

Encrypt

CA DLP prompts the user for a password, and uses this password to encrypt the file on the removable device.

Don't Encrypt

The file is copied onto the removable device unencrypted.

Cancel

The file is not copied.