Previous Topic: Encrypting Files Being CopiedNext Topic: Specify Which Removable Devices To Monitor


Overview

Data In Motion triggers in each user policy support Encrypt control actions. The Encrypt control actions can protect sensitive files when an employee copies them to removable devices or file sync folders.

For example, you can add Encrypt options to the policy of an employee who needs to take sensitive files home to work on them over the weekend. In this example, CA DataMinder encrypts these files when the employee copies them onto a removable device for the journey home. When the employee gets home, they run an encryption utility on the removable device to decrypt the files onto their home computer. In the morning, the process is reversed. When the employee copies the updated files from their home computer back onto the removable device, CA DataMinder re-encrypts the files. Finally, when the employee arrives back at the office, they run the same encryption utility again to decrypt the files and copy them from the USB device back onto their office computer.

In technical terms, the CA DataMinder Client File System Agent (CFSA) detects a file being copied and invokes Data In Motion triggers. If a trigger fires, an Encrypt control action gets applied to the file. A resulting advisory dialog then instructs the employee to protect the file by supplying a password that CA DataMinder uses to encrypt and decrypt the file.

To use this feature:

  1. Edit the machine policy on your CA DataMinder endpoint computers.
  2. Configure Data In Motion triggers to apply Encrypt actions to sensitive files.
  3. Educate your users so that they know how to use the CA DataMinder encryption utility when copying files.

These steps are described in the following sections.

Note: The CFSA cannot encrypt files being copied to network locations.