Managing exceptions
You can add, edit, duplicate and delete exceptions for your rules.
- When there is a transaction, rules are evaluated.
- If a rule is matched, its exception is evaluated, if any.
- If the exception is matched, the exception action is taken.
In other words, exceptions are evaluated only when their rules are matched. For example:
- The rule “Pizza” indicates that email messages from John Doe that have the word “pizza” in them should be encrypted.
- An exception to “Pizza” indicates that messages that include 5 instances of “pepperoni” should be quarantined.
As a result, messages from John Doe with both “pizza” and 5 instances of “pepperoni” are quarantined.
Unlike rules, exceptions cannot be cumulative.
You can add exceptions on the Manage DLP Policies or Manage Discovery Policies page in the Data Security module of the Forcepoint Security Manager ( or ).
You can select a rule in the tree, then select from the toolbar at the top of the content pane.
Like policies, exceptions have levels that define execution priority order. See Rearranging exceptions section for information on ordering exceptions.
You can duplicate an exception using an existing policy and its rules.