Setting file download controls

All managed cloud applications as well as custom applications support download DLP action for files. Forcepoint ONE SSE will process files as they are downloaded to look for the DLP pattern you have configured in your policy and then apply the appropriate action.

Block All File Downloads

In addition Forcepoint ONE SSE also supports the ability to block all file downloads preventing any files regardless of type, content, etc to be downloaded. You can select this underneath the Actions section and above the DLP table. If you select this option, you will notice the Download DLP table disappears since there would be no need to configure individual DLP policies with all files being blocked.



Download DLP Actions

If you choose to enforce DLP on download actions you will see the table and be able to add policy lines and configure which actions are taken based on which DLP patterns you wish to protect.



Note: If you select Forcepoint DLP as the data pattern, then FSM Enforced option gets populated in Action field as the action is provided from FSM. The FSM Enforced is the only option available for selection. Refer to Configuring FSM controlled policies for CASB and SWG channels to enable the Forcepoint DLP data pattern.

Scan Timeout (Deny Download)

At times files that are downloaded may be too large that Forcepoint ONE SSE cannot scan the file in time during the download action. In cases where the scan times out, customers can configure a policy to automatically deny the download action altogether to prevent possible data leakage attempts that bypass DLP scanning.

Under the Download DLP actions table, you can check the box Deny download on scan timeout. This means any file will automatically be denied from being downloaded if the DLP scan times out.