Skip to main content

SHIELD DRM Google

SHIELD DRM GoogleConditional policies are a feature that allows you to set and manage security policies for documents stored in Google Drive (My Drive, Shared Drives). You can decrypt DRM documents stored in Google Drive and convert them into regular documents.

This guide explains the components and configuration methods of the SHIELD DRM Google conditional policy.

This menu is설정 > 클라우드 서비스Displayed only if Google Workspace is selected. ExistingSHIELD DRM(Microsoft 365) policy andList of Separate PoliciesIt operates with __PH_0__, and the priorities of the two policies do not affect each other.


Differences with the existing SHIELD DRM (Microsoft 365) policy

itemSHIELD DRM (Microsoft 365)SHIELD DRM Google
Target StorageOneDrive · SharePoint · TeamsMy Drive · Shared Drive
Target Document TypeGeneral Document / DRM Document / MIP DocumentDRM Document
Document Execution PolicyEncryption with MIP / Document Deletion / Document DecryptionDocument Decryption
Document Path SpecificationYou can specify the folder path in storage.Drive Unit Specification (No Subdirectory Specification)
Document Event SpecificationFile creation/modification/upload, file movementNot applicable

Google Drive conditional policies include**There are no document event specification steps.**The policy registration screen and the policy list do not display any event trigger items.


Conditional Policy Components

SHIELD DRM Admin Page조건부 정책 > Cloud Storage > SHIELD DRM GoogleClick the menu to access the screen.

Policy List Table Structure

  • **Priority:**Indicates the order of policy implementation.
  • **Policy Name:**This is the unique name of the policy.
  • **Description:**The purpose of the policy or a brief description.
  • **Members:**Specify the users, groups, or policy groups to which the policy applies.
  • **Target Document:**This is the type of document to which the policy applies. If security level (C/S/O) conditions are set, those conditions will also be displayed.
  • **Document Path:**Displays the drives to which the policy applies (My Drive / Shared Drive).
  • **Document Encryption Policy:**This is the document encryption method to which the policy will be applied.
  • **Revision Date:**This is the date when the policy was last updated.

How to Register Conditional Policies

1. Policy Registration

정책 등록Click the button to enter the policy creation screen.

2. Enter Basic Policy Information

  • Policy Name(Required) : Enter the unique name of the policy.
  • Policy Description: You can enter the purpose of the policy or a brief description.
  • Member Designation(Required) : Select the user or group to which the policy will be applied.모든 사용자, can be specified for a specific user, group, or policy group.
  • Specify target document(Required) : The document subject to SHIELD DRM Google policy isDRM DocumentIt is. Unlike Microsoft 365 policies, general documents and MIP documents are not offered as optional.

(+) Additional settings when selecting the specified DRM document:

  • Check Constructor Information
    • Check if the document creator is the same as the logged-in user
    • Option: Same / Not the same
  • DRM Document Encryption Types
    • Select from DAC(ACL), MAC(Category), GRADE(Rating)
    • You can enter the related ID depending on the selected type.
  • DRM Document Permission Assignment
    • Check document permissions for logged-in users, creators, and added groups
    • Permission types: Read, Edit, Output, Export, Release, Change Permission, Print Marking, Validity Period
  • DRM encryption document release permission verification
    • When applying the document decryption policy, we also check whether the subject has decryption authority.
  • File Extension Specification
    • Specify the extension of the target DRM document.
  • Security Level (C/S/O) Conditions
    • You can additionally specify security level (label) conditions for the target document. Multiple selections are possible.
    • If you do not select a grade, all grades will be included.
    • The grade ID and label ID are mapped in pairs and are judged together, and the policy is applied only when all grade and label information of the target document matches.
  • Document Path Specification(Required) : Specify the Google Drive to which the enforcement policy will be applied.
    • 내 드라이브
    • 공유 드라이브
    • Both items can be selected multiple times,at least oneYou must select to save.
    • Unlike Microsoft 365 policies, the folder path within the drive is not specified, and the entire path of the selected drive is the target.

3. Setting Conditions

  • time: You can specify the time zone in which the policy will be applied.
    • 시간 제한 없음If you select __PH_0__, the policy will always be applied.
    • 등록된 시간에서 선택You can specify a specific time zone through __PH_0__.
    • You can set exception times so that policies do not apply during specific time zones.

4. Document Execution Policy Settings

The document enforcement policies that can be set in the SHIELD DRM Google policy are as follows.

  • **Document Decryption:**Decrypt the document and convert it to a regular document.

Provided in Microsoft 365 policiesMIP로 암호화, 문서 삭제is not provided by Google Drive policy.

5. Policy Settings

  • Usage status: You can set the activation or deactivation of the policy through the toggle button.
  • Expiration Date: You can specify a start date and an expiration date, and the expiration date무기한You can set it to.

6. Save and Complete

When all settings are complete,저장Click the button. It will be registered in the policy list, and you can modify or delete it afterwards.


Conditional Policy Editing

  • You can click on the policy to edit in the policy list to change the detailed settings.
  • Changing the order of the policy will reset the priority.
  • The policy copy, delete, and JSON edit functions are provided in the same way as the existing conditional policies.

Precautions

  • The policy name must be unique and cannot be duplicated.
  • Required fields must be filled in for the policy to be saved. If no drive is selected in the document path, it cannot be saved.
  • **The installation of a notification channel for changes to the target drive must precede the application of the policy.**Documents on drives where the channel is not installed are not subject to policies. Installation status is연동 관리 > Google Drive 이벤트 채널Check in.
  • If security level (C/S/O) conditions are set for the target document, the document's grade and label information must all match for the policy to be applied. If no conditions are set, the entire grade will be targeted.
  • Items with a high priority in the policy will be executed first.
  • When editing the policy, the changes will be applied only after clicking the save button.
  • Policy creation, modification, and deletion history is in the admin log.Google DriveIt is recorded as a policy type.
  • Use of the menuSHIELD DRM GoogleYou need role permissions.