Skip to main content

Policy Definition Document

Document version: v0.1

Target Product: SHIELD Gate
Scope: Business System Control (Top Level) · App Conditional Policy · URL Input Field Conditional Policy

SHIELD_Gate_Policy_Definition_Work_System_Conditional_Policy_v0.1.xlsx


0. Document Overview

  • This document is SHIELD GateBusiness System Conditional PolicyThe policy items that can be set by the administrator, by itemWhat to do / How it appears or is blocked to the user / Product recommendationsThis is the policy consultation sheet organized with __PH_0__.
  • During the introduction process, the client representative is responsible for each item.적용 정책Fill in the adoption value in the column to finalize the policy.

Default Provision vs Option (Separate Introduction) Distinction

The following items are**Not provided as a standard feature and requires separate implementation (optional)**Available for use only in the city. In the table[옵션]is represented as.

Option itemsContent
[옵션] SHIELD ViewerViewer for previewing in read-only mode without downloading the file
[옵션]SHIELDGate File Cabinet (SHIELDrive)Isolated storage for storing downloaded files in an isolated environment
[옵션]CDR DecontaminationFile Sanitization Engine. Required when using CDR download.

If the option is not introduced, the corresponding storage and inspection options will not be displayed on the policy screen or will be unavailable for selection. Please confirm the scope of introduction with the sales/deployment team.


1. Overview of Conditional Policies and Application Principles

1.1 Policy 3-Tier Structure

divisionDescriptionUser Screen and Actions When AppliedNote
Work System Control Conditional Policy (Top Level)Access permission for the app·URL input field menu itself, simultaneous screen number limitIf the menu is blocked, access is not possible regardless of the sub-policy.
App Conditional PolicyAccess and Isolation Security Policy by Registered AppAccess, block, and authenticate according to policy when the app is clicked.Target = App / App Group
Conditional Policy for URL Input FieldAccess and Isolation Security Policies by Site Accessed via URL Input FieldInput Address · Access · Block · Authentication According to PolicyTarget = All Sites / Registered Sites·Groups / Web Categories

⚠️ Top Priority Principle: Menus (app/URL input fields) that are not allowed in the top-level control policy cannot be accessed by users, regardless of any subordinate conditional policies set.

1.2 Priority Principle

itemDescriptionNote
Priority NumberThe smaller the number, the higher the priority (1 > 2 > 3 …)Drag and drop · Adjust with quick movement
Collision HandlingIf multiple policies apply under the same conditions, the most restrictive policy takes precedence.Exception policies are placed with high priority
Search Filter StatusPriority changes are not possible while applying search filters.Need to clear all filters when changing

1.3 Policy Evaluation Flow

  1. User Access (App Click or URL Input)
  2. Top-level control policy determination → Menu access permission status · Screen count verification
  3. Members·Conditions (Location·Time·Device) Judgment → Apply Policy Confirmation
  4. Access Policy Enforcement (Allow / Block / Additional Authentication)
  5. Usage Policy (Isolation Security Policy) Enforcement (Keyboard, File, Clipboard, etc.)
  6. Execution Result Reflection and Log Recording

2. Business System Control Conditional Policy (Top Level)

The top priority control policy that limits the number of screens that can be opened simultaneously and the business systems (app·URL input field) accessible by each member.

divisionSetting OptionsDescriptionUser Screen and Actions When AppliedRecommended PolicyNote
Policy NametextUnique name for policy identification (no duplicates allowed)Name to identify the targetRequired
MembersAll Users / Users·Groups (Assign·Exclude)Designating Policy Application TargetsApplied only to assigned members, excluded ones are not applied.group unit'All users' cannot be excluded
Target Business System — AppAllowed / Not AllowedAccess Permissions for Registered App ListAccess to app menu not allowed if not permittedAllow Group for Work NeedsIf not allowed, app conditional policy invalidation
Target Business System — URL Input FieldAllowed / Not AllowedDirect URL Input Function Access PermissionIf not allowed, URL input field cannot be usedDecision based on policyInvalid URL conditional policy if not allowed
Condition — LocationNo Limit / Registration LocationPolicy Application Scope Based on Connection IPConditions outside the location are not appliedConsideration of separating in-office and remote workManagement Center [Condition Item] Registration
Condition — TimeNo Limit / Registration TimeApplication Scope of Policy Based on Connection Time ZoneTime zones outside of the conditions are not applied.Specify Working Hourssame
Condition — DeviceNo Limit / Desktop·Tablet·MobileScope of Policy Application Based on Access DevicesDevices outside the conditions are not applicable.Review Limited to Work Terminalssame
Number of simultaneous screensNo limit / Up to N items (1 or more)Number of isolated browser screens that can be viewed simultaneouslyDisplay "Screen Opening Limit Notification" modal when trying to open a new screen after reaching the limit (close existing screen and retry)Differentiation by Job Type (See Notes Below)Resource Protection
Usage statusUse / Do not usePolicy Activation StatusNot working when not in useuse

3. Policy Basic Information (App / URL Input Field Common)

divisionSetting OptionsDescriptionUser Screen and Actions When AppliedRecommended PolicyNote
Policy NameText (up to 20 characters)Unique name for policy identificationName to identify target and grade clearlyRequired
DescriptionText (up to 200 characters)Policy Additional ExplanationOperating Intent DescriptionSelection
Members — AssignmentAll Users / User·Group SelectionSpecify the target for policy applicationPolicy actions only for assigned usersMinimize Scope of TargetGroup Unit Recommendation
Members — ExcludeUser·Group SelectionTarget for Policy Exemption Regardless of AllocationExcluded members have no policy impactSpecify exceptions only'All users' cannot be excluded
Target (App)App / App Group (Multiple)Specify the app to which the policy will be appliedApply policy only to selected appsSeparation by business appApp Policy Only
Target (URL)All Sites / Registered Sites·Groups / Web CategoriesSpecify the site to which the policy will be appliedApply policy only to selected targetsDefault Block (All Sites) + Selective AllowanceURL Policy Only

Target Setting Strategy (URL): Set "All Sites = Block Access" at a low priority, and allow specific sites and categories with a separate policy at a high priority.


4. Conditions (Connection Environment)

divisionSetting OptionsDescriptionUser Screen and Actions When AppliedRecommended PolicyNote
LocationAll Locations / Registered Locations (Exception Selection)Limit the scope of policy application based on connection IPThe policy does not apply outside the specified conditions.Separation by location such as in-office and remoteRegister Location in the [Condition Items] of the Management Center
timeAll Time / Registered Time (Exception Selection)Limit the scope of policy application based on access time zoneThe policy does not apply outside of the specified time frame.Specify Working HoursManagement Center [Condition Item] Register Time
DeviceAll Devices / Desktop / Tablet / MobilePolicy application based on the type of access devicePolicy not applied to devices outside the conditions.Review limited to work terminals (Desktop)

5. Execution Policy — Access Policy

divisionSetting OptionsDescriptionUser Screen and Actions When AppliedRecommended PolicyNote
Access PermissionAccess Allowed / Access DeniedDetermining the accessibility of the targetAccess unavailable when blocked, display guidance pageWork Target Allowance / Non-Work BlockingTop-level control
Additional AuthenticationNot Used / Email Verification / OTP VerificationAdditional identity verification required upon access permissionDisplay authentication screen → Access after authentication. If it fails, a popup "Authentication has failed." will appear, access not allowed.General target not used / Sensitive target OTPCan only be set in access allow policies.
Email Verification (Detailed)Display of authentication code input field, time limit 5 minutesEnter the code within 5 minutes. If not received, 'Resend verification code'Environment required for receiving emails
OTP Authentication (Detailed)Enter the authentication code after registering the initial QR code and recovery key.Initial Registration Screen → Enter OTP Code AfterwardsRecommended for High Security TargetsAuthentication app required

6. Isolation Security Policy (Usage Policy)

After access is granted, control user behavior within the isolated browser. Set all items to allow/block (or enable/disable).

divisionSetting OptionsDescriptionUser Screen and Actions When AppliedRecommended PolicyNote
Keyboard InputAllow / BlockControl of Keyboard Input in Isolated BrowserInput not allowed when blocked, display "Key input is prohibited due to policy." at the bottom center.Read-only targets are blocked
Site NavigationAllow / BlockControl of Moving to External Sites Outside the Target DomainAllowed: Free movement / Blocked: Only representative and related URLs can move, external movement will show "This action is prohibited by policy." guidance pageBlocking Work Systems / Allowing Search and PortalsSignificant Effect in URL Policy
File UploadAllow / Block (+Extension Restriction, Storage)Control of File Uploads to Isolated EnvironmentsBlocked uploads not allowed / Allowed only for specified extensions and storageAllowed only when necessary for workRepository: My PC File Folder /[옵션]SHIELDGate File Cabinet
File DownloadAllow / Block (+Extension Restriction, Storage)File Download Control in Isolated EnvironmentsBlocked: "This action is prohibited by policy. Downloading is prohibited by policy." Information page (returns upon closing)Differentiated by target gradeRepository details are below
└ Repository: My PC File FolderSelectionDownload to User's Local PCSave file locallyLow-risk subjects onlyDefault provided. Highest risk of leakage.
└ Repository: SHIELDGate File StorageSelection (SHIELDrive designation)Save to SHIELDrive storageStore in isolated storage instead of localRecommended Security Targets[옵션] **Separate introduction.**Members must be assigned to SHIELDrive storage to be available.
└ Repository: SHIELD ViewerSelectionRead-only preview instead of downloadView without receiving the original fileRecommended subjects for viewing only[옵션] **Separate introduction.**Subdivide into 3 options
└─ PDF DownloadAllow / BlockDownload the original after converting it to PDFOnly available for receipt as PDF when allowed.AllowedDefault: Allow (within SHIELD Viewer options)
└─ Download OriginalAllow / BlockDownload the original document as isUnable to receive original when blockedBlockDefault: Blocked
└─ CDR DownloadAllow / BlockDownload after CDR declassification processingPossible to receive a decontaminated version upon approvalBlockDefault: Block.[옵션] CDR engine required
Clipboard — Isolation → PCAllow / BlockCopy from the isolated browser to PCCopying is not allowed when blocked, display "Clipboard usage is prohibited due to policy." at the bottom center.BlockData Export Path
Clipboard — PC→IsolationAllow / BlockPasting in an isolated browser on PCCannot paste when blockedAllowedInput Convenience
Input Sensitive Information CheckAllow (Check) / Unused (+ Regular Expression Selection)Check and block input text with regular expressionsInput Blocking and Audit Log Recording during Pattern MatchingUsed for entering sensitive information[옵션] **Master Page Overlay (Company Unit) Introduction.**Regular Expression · Target Domain is managed in [Input Sensitive Information Management]
Session MaintenanceUsed / Unused (+Idle Time Min)Data Protection through Screen Lock during InactivityScreen lock after idle time, return with 'Refresh'Usage (according to idle time policy)Minute setting
Screen MarkingUsed / UnusedDisplay user identification watermark on the screenUsername·Email watermark displayed on the screenuseThe display method is customized in [Security Screen Settings].
Print WatermarkUsed / UnusedInserting User Identification Watermark on Printed MaterialsPrint with watermark includeduseThe display method is customized in [Security Screen Settings].
Video Conference ModeUsed / UnusedVideo Conference Performance Optimization ModeNo shortcut icon for SHIELDGate in the upper right corner during activation.Use only for video conference participantsPerformance Optimization Purpose
Context MenuUsage / Unused (+ Area-specific ON/OFF)Right-click menu control by areaOFF area does not display right-click menu, blocks associated shortcuts (e.g., Print OFF → blocks Ctrl+P)Use (Sensitive Items OFF)The details of the area are below.

6.1 Context Menu Area

areaRepresentative MenuUser Screen and Actions When AppliedRecommended PolicyNote
Page Background AreaBack, Forward, Refresh, Print, View Page Source, InspectDisplay right-click menu when ON / Hide when OFF · Block linked shortcut keysView Page Source · Inspect OFFClicking the top navigation button is not blocked (only shortcuts are blocked)
Text Selection AreaCopy, PrintDisplay on right-click after text drag / Not displayed when OFFSensitive Target Copy/Print OFF
linkOpen in new tab, Copy link addressDisplay on right-clicking the link / Not displayed when OFFMaintain default value (ON)
imageSave Image, Copy ImageDisplay on right-clicking the image / Not displayed when OFFThe download block target is storage OFF
videoPlay/Pause, Save VideoRight-clicking on the video shows / OFF does not showMaintain default value (ON)
AudioPlay/Pause, Save AudioRight-click on the audio to display / Not displayed when OFFMaintain default value (ON)
Input FieldCut, Copy, PasteRight-click on the input box to display / Not displayed when OFFClipboard Policy and Compliance Settings

If all items in the area are OFF, the right-click menu for that area will not be displayed.전체 ON / 전체 OFF / 초기화provided.


7. Policy Settings

divisionSetting OptionsDescriptionUser Screen and Actions When AppliedRecommended PolicyNote
Usage statusUse / Do not usePolicy Activation StatusPolicy does not operate when not in useuse
Expiration DateNot set / Period settingThe duration during which the policy operatesDoes not operate outside the periodNot set (indefinite)Set limited-time policy only

8. Policy Operation and Management (Reference)

divisionDescriptionNote
Priority ManagementDrag and Drop, Move to Top/Bottom, Directly Move NumberOnly possible when the search filter is disabled
Management of Default Execution PolicyAutomatic application of default execution and isolation security policies when registering a new policyApp·URL default is independently managed
Policy SearchSearch by policy name, members, target, conditions, execution policy, and usage status.AND between filters, OR within filters
Policy Application Status InquiryPeriod-specific Applied/Not Applied Policy Inquiry · Excel DownloadManaging Complexity through Non-Application Policy Summary
Import·ExportJSON (Backup·Restore) / Excel (Status·Reporting)ZIP for Multiple Selection