Classifiers

Policies use content classifiers to describe the data that is being protected. Content can be classified according to file properties, file labeling, key phrases, regular expression (regex) patterns, and dictionaries. Administrators can access the Classifiers in the cloud portal by navigating to Policy > Policy Elements > Classifiers.

The following classifiers are available:
Table 1.
Classifier Description
Patterns & Phrases Classify data using regex patterns, key phrases and dictionaries.
File labeling Classify data by using the labels attached by external labeling system(s).
File properties Classify data by file name, type, or size. File name identifies files by their extension. File type identifies files by their magic number (an internal identifier).

Forcepoint provides predefined classifiers for the most common use cases and administrators can also create custom classifiers to meet the organization's specific needs. See the section Predefined classifiers.

After classifying data, create a rule containing the content classifier and the conditions in which content should be considered a match. For example, if the content contains 3 keywords and an attachment over 2 MB, trigger an incident. In the rule, you define the sources and destinations to analyze.