Policy Definition Document
Document version: v0.1
Target Product: SHIELD Gate
Scope: Business System Control (Top Level) · App Conditional Policy · URL Input Field Conditional Policy
SHIELD_Gate_Policy_Definition_Work_System_Conditional_Policy_v0.1.xlsx
0. Document Overview
- This document is SHIELD GateBusiness System Conditional PolicyThe policy items that can be set by the administrator, by itemWhat to do / How it appears or is blocked to the user / Product recommendationsThis is the policy consultation sheet organized with __PH_0__.
- During the introduction process, the client representative is responsible for each item.
적용 정책Fill in the adoption value in the column to finalize the policy.
Default Provision vs Option (Separate Introduction) Distinction
The following items are**Not provided as a standard feature and requires separate implementation (optional)**Available for use only in the city. In the table[옵션]is represented as.
| Option items | Content |
|---|---|
[옵션] SHIELD Viewer | Viewer for previewing in read-only mode without downloading the file |
[옵션]SHIELDGate File Cabinet (SHIELDrive) | Isolated storage for storing downloaded files in an isolated environment |
[옵션]CDR Decontamination | File Sanitization Engine. Required when using CDR download. |
If the option is not introduced, the corresponding storage and inspection options will not be displayed on the policy screen or will be unavailable for selection. Please confirm the scope of introduction with the sales/deployment team.
1. Overview of Conditional Policies and Application Principles
1.1 Policy 3-Tier Structure
| division | Description | User Screen and Actions When Applied | Note |
|---|---|---|---|
| Work System Control Conditional Policy (Top Level) | Access permission for the app·URL input field menu itself, simultaneous screen number limit | If the menu is blocked, access is not possible regardless of the sub-policy. | |
| App Conditional Policy | Access and Isolation Security Policy by Registered App | Access, block, and authenticate according to policy when the app is clicked. | Target = App / App Group |
| Conditional Policy for URL Input Field | Access and Isolation Security Policies by Site Accessed via URL Input Field | Input Address · Access · Block · Authentication According to Policy | Target = All Sites / Registered Sites·Groups / Web Categories |
⚠️ Top Priority Principle: Menus (app/URL input fields) that are not allowed in the top-level control policy cannot be accessed by users, regardless of any subordinate conditional policies set.
1.2 Priority Principle
| item | Description | Note |
|---|---|---|
| Priority Number | The smaller the number, the higher the priority (1 > 2 > 3 …) | Drag and drop · Adjust with quick movement |
| Collision Handling | If multiple policies apply under the same conditions, the most restrictive policy takes precedence. | Exception policies are placed with high priority |
| Search Filter Status | Priority changes are not possible while applying search filters. | Need to clear all filters when changing |
1.3 Policy Evaluation Flow
- User Access (App Click or URL Input)
- Top-level control policy determination → Menu access permission status · Screen count verification
- Members·Conditions (Location·Time·Device) Judgment → Apply Policy Confirmation
- Access Policy Enforcement (Allow / Block / Additional Authentication)
- Usage Policy (Isolation Security Policy) Enforcement (Keyboard, File, Clipboard, etc.)
- Execution Result Reflection and Log Recording
2. Business System Control Conditional Policy (Top Level)
The top priority control policy that limits the number of screens that can be opened simultaneously and the business systems (app·URL input field) accessible by each member.
| division | Setting Options | Description | User Screen and Actions When Applied | Recommended Policy | Note |
|---|---|---|---|---|---|
| Policy Name | text | Unique name for policy identification (no duplicates allowed) | — | Name to identify the target | Required |
| Members | All Users / Users·Groups (Assign·Exclude) | Designating Policy Application Targets | Applied only to assigned members, excluded ones are not applied. | group unit | 'All users' cannot be excluded |
| Target Business System — App | Allowed / Not Allowed | Access Permissions for Registered App List | Access to app menu not allowed if not permitted | Allow Group for Work Needs | If not allowed, app conditional policy invalidation |
| Target Business System — URL Input Field | Allowed / Not Allowed | Direct URL Input Function Access Permission | If not allowed, URL input field cannot be used | Decision based on policy | Invalid URL conditional policy if not allowed |
| Condition — Location | No Limit / Registration Location | Policy Application Scope Based on Connection IP | Conditions outside the location are not applied | Consideration of separating in-office and remote work | Management Center [Condition Item] Registration |
| Condition — Time | No Limit / Registration Time | Application Scope of Policy Based on Connection Time Zone | Time zones outside of the conditions are not applied. | Specify Working Hours | same |
| Condition — Device | No Limit / Desktop·Tablet·Mobile | Scope of Policy Application Based on Access Devices | Devices outside the conditions are not applicable. | Review Limited to Work Terminals | same |
| Number of simultaneous screens | No limit / Up to N items (1 or more) | Number of isolated browser screens that can be viewed simultaneously | Display "Screen Opening Limit Notification" modal when trying to open a new screen after reaching the limit (close existing screen and retry) | Differentiation by Job Type (See Notes Below) | Resource Protection |
| Usage status | Use / Do not use | Policy Activation Status | Not working when not in use | use |
3. Policy Basic Information (App / URL Input Field Common)
| division | Setting Options | Description | User Screen and Actions When Applied | Recommended Policy | Note |
|---|---|---|---|---|---|
| Policy Name | Text (up to 20 characters) | Unique name for policy identification | — | Name to identify target and grade clearly | Required |
| Description | Text (up to 200 characters) | Policy Additional Explanation | — | Operating Intent Description | Selection |
| Members — Assignment | All Users / User·Group Selection | Specify the target for policy application | Policy actions only for assigned users | Minimize Scope of Target | Group Unit Recommendation |
| Members — Exclude | User·Group Selection | Target for Policy Exemption Regardless of Allocation | Excluded members have no policy impact | Specify exceptions only | 'All users' cannot be excluded |
| Target (App) | App / App Group (Multiple) | Specify the app to which the policy will be applied | Apply policy only to selected apps | Separation by business app | App Policy Only |
| Target (URL) | All Sites / Registered Sites·Groups / Web Categories | Specify the site to which the policy will be applied | Apply policy only to selected targets | Default Block (All Sites) + Selective Allowance | URL Policy Only |
Target Setting Strategy (URL): Set "All Sites = Block Access" at a low priority, and allow specific sites and categories with a separate policy at a high priority.
4. Conditions (Connection Environment)
| division | Setting Options | Description | User Screen and Actions When Applied | Recommended Policy | Note |
|---|---|---|---|---|---|
| Location | All Locations / Registered Locations (Exception Selection) | Limit the scope of policy application based on connection IP | The policy does not apply outside the specified conditions. | Separation by location such as in-office and remote | Register Location in the [Condition Items] of the Management Center |
| time | All Time / Registered Time (Exception Selection) | Limit the scope of policy application based on access time zone | The policy does not apply outside of the specified time frame. | Specify Working Hours | Management Center [Condition Item] Register Time |
| Device | All Devices / Desktop / Tablet / Mobile | Policy application based on the type of access device | Policy not applied to devices outside the conditions. | Review limited to work terminals (Desktop) |
5. Execution Policy — Access Policy
| division | Setting Options | Description | User Screen and Actions When Applied | Recommended Policy | Note |
|---|---|---|---|---|---|
| Access Permission | Access Allowed / Access Denied | Determining the accessibility of the target | Access unavailable when blocked, display guidance page | Work Target Allowance / Non-Work Blocking | Top-level control |
| Additional Authentication | Not Used / Email Verification / OTP Verification | Additional identity verification required upon access permission | Display authentication screen → Access after authentication. If it fails, a popup "Authentication has failed." will appear, access not allowed. | General target not used / Sensitive target OTP | Can only be set in access allow policies. |
| Email Verification (Detailed) | — | Display of authentication code input field, time limit 5 minutes | Enter the code within 5 minutes. If not received, 'Resend verification code' | — | Environment required for receiving emails |
| OTP Authentication (Detailed) | — | Enter the authentication code after registering the initial QR code and recovery key. | Initial Registration Screen → Enter OTP Code Afterwards | Recommended for High Security Targets | Authentication app required |
6. Isolation Security Policy (Usage Policy)
After access is granted, control user behavior within the isolated browser. Set all items to allow/block (or enable/disable).
| division | Setting Options | Description | User Screen and Actions When Applied | Recommended Policy | Note |
|---|---|---|---|---|---|
| Keyboard Input | Allow / Block | Control of Keyboard Input in Isolated Browser | Input not allowed when blocked, display "Key input is prohibited due to policy." at the bottom center. | Read-only targets are blocked | |
| Site Navigation | Allow / Block | Control of Moving to External Sites Outside the Target Domain | Allowed: Free movement / Blocked: Only representative and related URLs can move, external movement will show "This action is prohibited by policy." guidance page | Blocking Work Systems / Allowing Search and Portals | Significant Effect in URL Policy |
| File Upload | Allow / Block (+Extension Restriction, Storage) | Control of File Uploads to Isolated Environments | Blocked uploads not allowed / Allowed only for specified extensions and storage | Allowed only when necessary for work | Repository: My PC File Folder /[옵션]SHIELDGate File Cabinet |
| File Download | Allow / Block (+Extension Restriction, Storage) | File Download Control in Isolated Environments | Blocked: "This action is prohibited by policy. Downloading is prohibited by policy." Information page (returns upon closing) | Differentiated by target grade | Repository details are below |
| └ Repository: My PC File Folder | Selection | Download to User's Local PC | Save file locally | Low-risk subjects only | Default provided. Highest risk of leakage. |
| └ Repository: SHIELDGate File Storage | Selection (SHIELDrive designation) | Save to SHIELDrive storage | Store in isolated storage instead of local | Recommended Security Targets | [옵션] **Separate introduction.**Members must be assigned to SHIELDrive storage to be available. |
| └ Repository: SHIELD Viewer | Selection | Read-only preview instead of download | View without receiving the original file | Recommended subjects for viewing only | [옵션] **Separate introduction.**Subdivide into 3 options |
| └─ PDF Download | Allow / Block | Download the original after converting it to PDF | Only available for receipt as PDF when allowed. | Allowed | Default: Allow (within SHIELD Viewer options) |
| └─ Download Original | Allow / Block | Download the original document as is | Unable to receive original when blocked | Block | Default: Blocked |
| └─ CDR Download | Allow / Block | Download after CDR declassification processing | Possible to receive a decontaminated version upon approval | Block | Default: Block.[옵션] CDR engine required |
| Clipboard — Isolation → PC | Allow / Block | Copy from the isolated browser to PC | Copying is not allowed when blocked, display "Clipboard usage is prohibited due to policy." at the bottom center. | Block | Data Export Path |
| Clipboard — PC→Isolation | Allow / Block | Pasting in an isolated browser on PC | Cannot paste when blocked | Allowed | Input Convenience |
| Input Sensitive Information Check | Allow (Check) / Unused (+ Regular Expression Selection) | Check and block input text with regular expressions | Input Blocking and Audit Log Recording during Pattern Matching | Used for entering sensitive information | [옵션] **Master Page Overlay (Company Unit) Introduction.**Regular Expression · Target Domain is managed in [Input Sensitive Information Management] |
| Session Maintenance | Used / Unused (+Idle Time Min) | Data Protection through Screen Lock during Inactivity | Screen lock after idle time, return with 'Refresh' | Usage (according to idle time policy) | Minute setting |
| Screen Marking | Used / Unused | Display user identification watermark on the screen | Username·Email watermark displayed on the screen | use | The display method is customized in [Security Screen Settings]. |
| Print Watermark | Used / Unused | Inserting User Identification Watermark on Printed Materials | Print with watermark included | use | The display method is customized in [Security Screen Settings]. |
| Video Conference Mode | Used / Unused | Video Conference Performance Optimization Mode | No shortcut icon for SHIELDGate in the upper right corner during activation. | Use only for video conference participants | Performance Optimization Purpose |
| Context Menu | Usage / Unused (+ Area-specific ON/OFF) | Right-click menu control by area | OFF area does not display right-click menu, blocks associated shortcuts (e.g., Print OFF → blocks Ctrl+P) | Use (Sensitive Items OFF) | The details of the area are below. |
6.1 Context Menu Area
| area | Representative Menu | User Screen and Actions When Applied | Recommended Policy | Note |
|---|---|---|---|---|
| Page Background Area | Back, Forward, Refresh, Print, View Page Source, Inspect | Display right-click menu when ON / Hide when OFF · Block linked shortcut keys | View Page Source · Inspect OFF | Clicking the top navigation button is not blocked (only shortcuts are blocked) |
| Text Selection Area | Copy, Print | Display on right-click after text drag / Not displayed when OFF | Sensitive Target Copy/Print OFF | |
| link | Open in new tab, Copy link address | Display on right-clicking the link / Not displayed when OFF | Maintain default value (ON) | |
| image | Save Image, Copy Image | Display on right-clicking the image / Not displayed when OFF | The download block target is storage OFF | |
| video | Play/Pause, Save Video | Right-clicking on the video shows / OFF does not show | Maintain default value (ON) | |
| Audio | Play/Pause, Save Audio | Right-click on the audio to display / Not displayed when OFF | Maintain default value (ON) | |
| Input Field | Cut, Copy, Paste | Right-click on the input box to display / Not displayed when OFF | Clipboard Policy and Compliance Settings |
If all items in the area are OFF, the right-click menu for that area will not be displayed.
전체 ON / 전체 OFF / 초기화provided.
7. Policy Settings
| division | Setting Options | Description | User Screen and Actions When Applied | Recommended Policy | Note |
|---|---|---|---|---|---|
| Usage status | Use / Do not use | Policy Activation Status | Policy does not operate when not in use | use | |
| Expiration Date | Not set / Period setting | The duration during which the policy operates | Does not operate outside the period | Not set (indefinite) | Set limited-time policy only |
8. Policy Operation and Management (Reference)
| division | Description | Note |
|---|---|---|
| Priority Management | Drag and Drop, Move to Top/Bottom, Directly Move Number | Only possible when the search filter is disabled |
| Management of Default Execution Policy | Automatic application of default execution and isolation security policies when registering a new policy | App·URL default is independently managed |
| Policy Search | Search by policy name, members, target, conditions, execution policy, and usage status. | AND between filters, OR within filters |
| Policy Application Status Inquiry | Period-specific Applied/Not Applied Policy Inquiry · Excel Download | Managing Complexity through Non-Application Policy Summary |
| Import·Export | JSON (Backup·Restore) / Excel (Status·Reporting) | ZIP for Multiple Selection |