Exception Policy Settings
[Policy] > [Basic Demilitarization Policy] > [Exception] Settings
Among the decontamination policies of the SHIELDEX File,'Exception' settingis an item that allows for the circumvention of general security policies or defines exceptions in specific situations.
Exception settings allow for detailed control over the sanitization of documents or the import of originals based on file extensions and conditions.
⚠️ The permission to set the basic de-identification policy is granted to [Administrator Type - System Administrator], and
Administrator permission settings can be found under [Administrator Settings] > [Account and Permission Management].
Detailed Description of Settings Items
| Policy Name | Description |
|---|---|
| Forced Import Settings for Specific Extensions | Specify the file extensions that can be imported in their original state without decontamination, separated by semicolons. Input example) exe;bat;cmd; |
| Blocked Exception Settings for Unsupported Extensions | Unsupported extensions are handled by the 'Unsupported Extension Block Settings' value in the 'Common' tab, but extensions specified as exceptions in this item allow for original imports. Input example) log;tmp; |
| Exception settings for blocking extension forgery | Files with extension spoofing are handled by the 'Extension Spoofing Block Settings' value in the 'Common' tab, but file types (MIME types) specified as exceptions in this item allow original imports. input example) application/zip;application/x-rar-compressed; |
| Unspecified Extension File Import Settings | Set the handling method for files without an extension. Files without extensions are considered to be of an unclear type for security reasons, so it is recommended to set up blocking. |
| Original Import Settings When Threat Elements Are Not Detected | Set the handling of documents that do not contain threats such as OLE objects, macros, scripts, and ActiveX. Documents without threats can be brought back in their original state, preserving the format and content of the document. |
| Import settings for the original when a decontamination error occurs | Set the handling method for cases where the demilitarization cannot be completed normally due to demilitarization engine errors, processing failures, system exceptions, etc. |
| Original Import Settings on Timeout | Set the handling method for cases where the decontamination work is not completed within the time specified in 'Set Operation Time Out Criteria'. (Items where individual policy application is not possible) |
| Setting the timeout criteria (minutes) | Set the maximum time allowed for decontamination processing in minutes. If the specified time is exceeded, it will be processed according to "Original Import Settings on Job Timeout." (Items where individual policy application is not possible) |
Input Rules and Precautions
- The extension input must be**Separated by semicolons (;)**must be done, and enter without spaces.
- 'Setting the timeout criteria' is an important benchmark in actual demilitarization processing, so an appropriate time should be set according to performance testing.
- Importing 'files with unspecified extensions' can pose security vulnerabilities, so it should be configured carefully in conjunction with internal security policies.
Reference Notes
- After the policy change, you can check the change history in [Policy Change History], and if necessary, you can also restore the policy.