Content rule templates

Content rules are applied to policy routes to provide specific instructions about what the security policy is looking for, and what to do when it triggers. When you create a content rule, you must select a Content Rule Template on which to base your rule.

Content rules look for conditions that match the What To Look For? clauses and apply the What To Do? actions that have been configured.

Choose your content rule template carefully, as it determines which What To Look For? clauses are included.

  You can change the suggested What To Do? actions and add additional actions if required.

Clearswift Gateway provides the following Content Rule templates:

Template What the rule does... What to Look For? clauses Default Disposal/Primary Action
Add Disclaimer Adds an annotation (such as a disclaimer) to the message. Always Trigger the Rule Annotate the message
Add Disclaimer Conditionally

Detects messages with particular media types and expressions, and appends an annotation (such as a disclaimer) to the message.

The lexical expression clause operates in conjunction with the selected media types in this content rule. The rule will only apply when the lexical expression is triggered in any attachment or part of a message that matches the media types you have selected.

Which Media Types, Lexical Expression Annotate the message
All Traffic Allows all traffic. Always Trigger the Rule Deliver/Continue
Analyze Properties Analyzes document properties for specific lexical expressions. Analyze Properties, Which Media Types, Size Restriction Deliver/Continue
Archive to Server Sends a copy of the message to a relay server. Always Trigger the Rule

Send a Copy (Relay Server)

Attachment Count Restriction Detects messages with an excessive number of attachments, based on a user-specified attachment limit. Restrict the Number of Attachments Deliver the message
Check Registered Data

Detects data that has been registered on the Information Governance Server.

Which Media Types, Classification LevelClosed The Classification Level specifically relates to values that are assigned to items that have been registered on an IG Server. The disposal action will trigger where content passing through the Gateway is matched to content registered on the IG Server, and where the Classification level for the item as set on the IG server is equal or exceeds the level set on the Gateway. If this value is set to 0 on your Gateway, matches to any IG registered items will trigger the disposal action., Scan text extracted from images (OCR)

Deliver/Continue
Detect Active Content Detects active content (such as macros) in selected media types. Which Media Types Deliver/Continue
Detect Filenames

Detects and processes selected filenames based on Filename Lists.

Filename Deliver/Continue
Detect Lexical Expression

Detects and processes unacceptable lexical expressions in selected media types.

Note: If you want to scan scripts in the content, select the Scan Embedded Script option and use the Which Media Types clause to include a selection of media types.

Note: If you want to scan text extracted from images using OCR, you must also select Scan body in the Lexical Expression clause.

Lexical Expression, Which Media Types, Size Restriction, Scan text extracted from Images (OCR) Deliver/Continue
Detect Malformed Data Detects content containing 'bad', corrupted, or malformed data. Which media types Hold in the Message Processing Failure area/ Allow the communication
Detect Media Types

Detects and processes selected media types.

Which Media Types, Size Restriction Filename Deliver/Continue
Detect Spam Detects spam using a selection of SpamLogic methods. Spam Detection Deliver the message
Detect Unacceptable Images Detects messages with unacceptable images, based on a user-specified threshold. Unacceptable Images Deliver the message
Detect Virus Detects viruses and Malware (including Sandboxing). Virus Detection, Malware Outbreak Detection, Scan with sandbox

Hold in Virus area (if detected)

Hold in Message Processing Failure area (if unsuccessful)

Digital Signature Validation Detects valid digital signatures. Digital Signature Validation Hold in Message Processing Failure area
Encryption or Decryption Fails Detects messages that have failed to be encrypted or decrypted. Cryptographic Failure Hold in Message Processing Failure area
Message Modification Fails Detects and processes messages that the Gateway has not been able to modify. Message has failed to be modified Hold in Message Processing Failure area
Message Processing Fails Detects messages that the Gateway has been unable to process. Message has failed to be processed Hold in Message Processing Failure area
Message Size Restriction Detects messages that exceed a user-specified size limit. Size Restriction Deliver the message
Missing Manager Detects messages that do not include the sender's manager when a manager relationship is defined. Missing Manager Detection

No action (if detected)

No action (if not in relationships list)

Redact Text

Detects unacceptable lexical expressions in selected media types. Attempts to redact content.

Note: If you want to scan text extracted from images using OCR, you must also select Scan body in the Lexical Expression clause.

Lexical Expression, Which Media Types, Size Restriction, Bypass Rule, Scan text extracted from Images (OCR)

Deliver/Continue (if successful)

Deliver the message (if unsuccessful)

Run External Command Runs an executable program that performs processing on a file type that the Gateway does not support by default. Which Media Type, Run External Command

No action (if detected)

No action (if modified)

Sanitize Active Content Detects active content (such as macros) in selected media types. Attempts to sanitize content. Which Media Types, Bypass Rule

Deliver/Continue (if successful)

Deliver the message (if unsuccessful)

Sanitize Document Content Detects metadata and document properties in selected document areas and selected media types. Attempts to sanitize content. Which Media Types, Bypass Rule, Contains Any Of The Following

Deliver/Continue (if successful)

Deliver the message (if unsuccessful)

Sanitize Message Detects messages containing URLs, hyperlinks, and active content in the message subject or body. Which Message Types, Mode, HTML and RTF Email Bodies, URLs and Hyperlinks

No action (if detected)

No action (if modified)

Send a Copy (BCC) Sends copies of messages to a specified email address. Always Trigger the Rule No action
Structural Validation

Checks for appended data in certain format types.

Always Trigger the Rule Deliver/Continue

See also...

 

References to Web policy content are only available when a Web Gateway is included in the peer group.