We implemented Data Control policy in our network. Any one transfer data to USB device will create logs in SEC
My questions is
- Scenario: A staffperson is offloading a significant amount of sensitive information
- Questions:
- Would (or could) this activity be highlighted in a fashion on the Sophos console so that it would be brought to our attention? Or, do we simply need to review the detailed logs?
- Can we implement thresholds that would provide us notification based on:
- The frequency with which a specific staffperson is offloading data.
- The amount of data being transferred
- The type of data being transferred.
This thread was automatically locked due to age.