Conditional Policy - Endpoint
Overview
The conditional policy Endpoint feature manages document security policies on a Local PC with Document Security 6 installed. This feature allows for the conversion of regular documents to MIP documents or DRM documents, as well as mutual conversion between MIP documents and DRM documents. Within a single policy, document conversion, security level designation, and upload blocking can be configured together.
Purpose
- Set the conditional policy for the Local PC with Document Security 6 installed through the admin page.
- Automate the state transitions and security management of documents through conditional policies.
Prerequisites
- The Local PC subject to conditional policies must have Document Security 6 or higher installed.
- The local PC must be logged in to both Security365 and the SCI Server (Document Security server).
Policy Configuration Guide
- The policy name must be unique and cannot be duplicated.
- Required fields (*) must be filled in for the policy to be saved.
- You must select at least one extension when specifying the extension.
- Members added to the exclusion list will not be subject to the policy, even if they are included in the assignment list.
- If you navigate to another page without saving when there are policy changes, the changes will be lost.
- If there are multiple execution policy cards, you can change the order of the cards using drag and drop.
Json Code Editor
When clicking an item in the registered policy list, in the top menu,JSON 보기You can use the feature. It shows the conditional policy for the registered policy in JSON code format and supports editing and saving functions. If there are multiple enforcement policies (cards) configured, they will be displayed and saved in an array format in JSON as well. During manual work, if there are syntax errors, the policy may not function properly, so thorough review is recommended.
Policy Creation and Option Settings
After logging into the admin page, navigate to [Conditional Policy] → [Endpoint] → [Document Security] menu.정책 등록Click the button and configure the information of the policy.
Policy Basic Information
| Settings Items | Explanation |
|---|---|
| Policy Name | Enter the unique name of the policy. (No duplicates allowed) |
| Policy Description | Enter description information about the policy. |
Members
| Settings Items | Explanation |
|---|---|
| allocation | Specify the users, groups, or policy groups to which the policy will be applied. |
| exclusion | Specify the members to be excluded from policy application. Excluded members will not be subject to the policy even if they are added to the assignment. |
Allocation Settings Options:모든 사용자(Applies to all users within the registered organization) /사용자 및 그룹 선택(Only applies to specified users and groups)
Target Document | General Document
| Setting Options | Explanation |
|---|---|
| Not applied | General documents are excluded from the subject. |
| All general documents | All general documents will be targeted. |
| File Extension Specification | Only documents of the selected extensions are eligible. (doc, docx, xls, xlsx, xlsb, xlsm, ppt, pptx, pps, ppsx, pptm, pdf, zip) |
Target Document | DRM Document
| Setting Options | Explanation |
|---|---|
| Not applied | DRM documents are excluded from the subject. |
| All DRM documents | All DRM documents are subject to this. |
| Designated DRM Document | Only DRM documents that meet specific conditions will be targeted. |
Additional settings when selecting the specified DRM document:
- Constructor Verification: After checking whether the document creator is the same as the currently logged-in user, apply the policy accordingly.
- Constraints: The option is only exposed when the multi-server registration feature along the path [Integration Management] → [Document Security] is enabled.
- Option: Enabled / Disabled (In the case of Enabled, specify "Policy applies when the document creator and the logged-in user match" / "Policy applies when they do not match")
- DRM Document Encryption Types: Select from DAC(ACL), MAC(category), GRADE(level). Depending on the selected type, you can enter the related ID.
- DRM Document Permissions: Check document permissions for logged-in users, creators, and added groups (read, edit, output, export, release, change permissions, print marking, validity period)
- File Extension Specification: Specify the extension of the target DRM document (doc, docx, xls, xlsx, xlsb, xlsm, ppt, pptx, pps, ppsx, pptm, pdf)
Target Document | MIP Document
| Setting Options | Explanation |
|---|---|
| Not applied | MIP documents are excluded from the subject. |
| All MIP documents | All MIP documents are subject to this. |
| Designated MIP Document | Only MIP documents that meet specific conditions will be targeted. |
Additional settings when selecting the specified MIP document:
- Labeling: Use MIP label information as a condition
- File Extension Specification: Specify the extension of the target MIP document (doc, docx, xls, xlsx, xlsb, xlsm, ppt, pptx, pps, ppsx, pptm, pdf)
Common Settings
Security Label Verification: This is an option used to determine whether a security label is applied to the document and its status, and to designate and change the security level.
| Setting Options | Explanation |
|---|---|
| Not confirmed | Referring to all selected document types regardless of security label status |
| Document with specified label as target | Referring to document types that have security labels applied |
| Targeting documents without labels | Refers to document types that do not have a security label applied. |
zip,pptmThe extension is a format that does not support security labels and is excluded from label verification targets.
Document Path Specification
| Settings Items | Explanation |
|---|---|
| All Paths | Policies are applied to files in all paths. |
| designated path | Policies are applied to files in the specified path. (Manual entry or default paths: %WINDIR%, %PROGRAMFILES%, %PROGRAMDATA%, %USERS%, %TEMP%) |
Document Events
- Mouse Right-Click Menu
- Right-click the mouse and click on the [Encrypt Document] menu.
- Right-click the mouse and click the [Document Conversion] menu.
- Right-click the mouse and click on the [Document Grade Setting] menu.
- Right-click the mouse and click the [Delete MIP Label] menu.
- ※ Conversion types 3 ([General Document Encryption] / [Document Conversion] / [MIP Label Removal]) and [Document Classification Setting] cannot be selected at the same time.
- Document Usage Method
- Document Viewing/Editing and Exit (or Save)
- Document Viewing
- Local Explorer
- Moving/Copying Files in OneDrive
- Moving/Copying Files to OneDrive
- Moving/Copying Files in SharePoint
- Moving/Copying Files in SharePoint
- Cloud
- Downloading Files from the Cloud
- Teams
- Upload Files with Teams Copilot
Setting Conditions
Location (IP)
| Setting Options | Explanation |
|---|---|
| No location restrictions | Policies are applied to all locations (IP). |
| Select from registered locations | Select a specific location to apply the policy. |
time
| Setting Options | Explanation |
|---|---|
| No time limit | The policy applies at all times. |
| Select from registered time | Select a specific time to apply the policy. |
Document Execution Policy
The execution policy area isDocument Conversioncard andApplication of Document Security LevelsIt consists of cards. If the upload-related document event is selected, thenUpload BlockedAdditional cards will be displayed.
Card Composition and Execution Order
- Document transformation cards and document security level application cards can be reordered by the administrator using drag and drop, and the card at the top will be executed first.
- The top (first) card isEssentialis treated as a failure, and the entire execution will be halted. Subcards areOptionIt is treated as a failure, but the overall result is processed as a success (failure details are logged).
- If the selected document event does not require any cards, those cards will be automatically disabled and fixed with the non-executive options (conversion card: "Maintain Status" / grade card: "Maintain Grade").
Document Conversion Card
| Setting Options | Explanation |
|---|---|
| Encryption with DRM | Encrypt the target document with DRM. (Forcefully encrypt all target documents or apply according to the DRM encryption type (DAC/MAC/GRADE)) |
| Encryption with MIP | Select the MIP label to apply to the target document. |
| Maintain State | The status of the target document is not changed. It is mainly used for exception handling. |
| Delete MIP Label | Deletes the assigned MIP label when the event specified in the target document occurs. |
Document Security Level Application Card
| Setting Options | Explanation |
|---|---|
| Grade Maintenance | The security level of the target document will not be changed. |
| Security Level Settings | Assign or change the security level for the target document. The detailed UI will switch responsively according to the selected document event configuration. |
Responsive UI for Security Level Settings
- If the document event includes a right-click [Set Document Grade](<Manually Specify Grade>): Query the grade information from the Security365 Management Center to expose the grade to the client.Multiple selectionYou need to specify items to be displayed as the basic grade among the selected grades. The actual label selection is done on the client when the user right-clicks.
- If the document events consist only of implicit events such as end/save, view, etc.: destination1 grade + 1 labelSwitches to a UI that specifies, and is automatically applied with the designated grade and label.
- Changing the document event configuration will change the above judgment, so the already entered rating settings may be reset after a warning.
Upload Block Card
- This is an ON/OFF toggle card that is displayed only when one of the events for moving/copying files to OneDrive/SharePoint or uploading files with Teams Copilot is selected.
- The block target grade is not a card but rather**[Target Document] > Check Security Label**specifies.
- Execution order of applying document conversion and document security grade cards isindependentIt operates as. If upload blocking is ON, the conversion and rating cards will not execute in that upload event, but it does not affect the order setting between the conversion and rating cards themselves.
- When uploading multiple files at once, each file is assessed individually, and the blocking or allowing results are provided.
- It can be applied to regular documents regardless of encryption status.
Display Policy List
The execution policy is displayed as a single column in the list. If multiple cards are set, the value of each card is|Displays in a single cell separated by a comma. (e.g.:MIP로 암호화 | S등급 자동)
Policy Settings
Usage status
| Setting Options | Explanation |
|---|---|
| ON | Activating the policy. |
| OFF | Disabling the policy. |
Expiration Date
| Setting Options | Explanation |
|---|---|
| No expiration date | No expiration date is set for the policy. |
| Expiration Date Setting | Set the start date and expiration date. (The expiration date can be set to indefinite) |