US2019354691A1PendingUtilityA1

Data detection and protection policies for electronic file systems

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Jul 10, 2012Filed: Jun 19, 2019Published: Nov 21, 2019
Est. expiryJul 10, 2032(~6 yrs left)· nominal 20-yr term from priority
H04L 51/063G06F 21/60H04L 51/34H04L 51/12H04L 51/234H04L 51/212
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and/or methods for deploying and implementing data loss prevention (DLP) policy definition that may encapsulate the requirements, control objectives and directives, and/or the definitions of sensitive data types as stipulated directly or indirectly by the regulatory policy are disclosed. In one embodiment, DLP policies may be identified by an organization to run on top of a set of electronic file systems (e.g., email systems, file systems, web servers and the like). Organizations and their administrators may implement a set of DLP policy instance which are derived from DLP policy templates. DLP policy templates may comprise both structure and meaning—and may acquire a given DLP policy by the replacement of parameterized expressions with desired parameter values. In another embodiment, the state of the DLP policy instance may change according to the lifecycle of the policy instance deployment.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method performed by a computing system, the method comprising:
 identifying a DLP policy template configured to install a data loss prevention (DLP) policy instance for an electronic file system;   creating a DLP policy template definition that defines a property to be mapped to a deployment value at a time the DLP policy template is used to create the DLP policy instance;   creating a main DLP policy object derivable from the DLP policy template definition and configured to track shared metadata and state of the DLP policy instance;   creating a policy rule object defining a policy directive as a match condition and an action derivable from the main DLP policy object; and   creating a data classification rule object defining electronic data associated with the electronic file system to which the policy rule object is applied.   
     
     
         22 . The method of  claim 21 , wherein the electronic file system comprising a file server configured to communicate with a client, the client configured to request access to data and upload data to the file server. 
     
     
         23 . The method of  claim 22 , wherein the DLP policy instance is implemented for a plurality of electronic file systems, each electronic file system comprising one or more file servers, each file server configured to communicate with a plurality of clients. 
     
     
         24 . The method of  claim 23 , wherein the DLP policy template comprises a set of template component fields and is generic to the plurality of electronic file systems, the method further comprising:
 transforming the generic DLP policy template into a first DLP policy instance that is specific to a first electronic file system by parameterizing the set of template component fields based on a first file system characteristic representing operation of the first electronic file system; and   transforming the generic DLP policy template into a second DLP policy instance that is specific to a second electronic file system by parameterizing the set of template component fields based on a second file system characteristic representing operation of the second electronic file system.   
     
     
         25 . The method of  claim 24 , wherein the first electronic file system is configured to provide a first service that is different than a second service provided by the second electronic file system. 
     
     
         26 . The method of  claim 21 , wherein creating a DLP policy template comprises:
 creating a set of policy template operations, each policy template operation configured to operate upon the DLP policy template.   
     
     
         27 . The method of  claim 26 , wherein each policy template operation comprises at least one of:
 an install operation, a remove operation, an import operation, an export operation, a query operation, or a delete operation.   
     
     
         28 . The method of  claim 21 , wherein creating a main DLP policy object comprises:
 creating a set of main DLP policy object operations, each DLP policy object operation configured to act upon the DLP policy object.   
     
     
         29 . The method of  claim 28 , wherein at least one of the main DLP policy object operations comprises creating a new policy object. 
     
     
         30 . The method of  claim 28 , wherein each main DLP policy object operation comprises at least one:
 creating a new state change, editing a state change, or deleting a state change.   
     
     
         31 . A computing system comprising:
 at least one processor; and   memory storing instructions executable by the at least one processor, wherein the instructions, when executed, configure the computing system to:
 identify a DLP policy template configured to install a data loss prevention (DLP) policy instance for an electronic file system; 
 create a DLP policy template definition that defines a property to be mapped to a deployment value at a time the DLP policy template is used to create the DLP policy instance; 
 create a main DLP policy object derivable from the DLP policy template definition and configured to track shared metadata and state of the DLP policy instance; 
 create a policy rule object defining a policy directive as a match condition and an action derivable from the main DLP policy object; and 
 create a data classification rule object defining electronic data associated with the electronic file system to which the policy rule object is applied. 
   
     
     
         32 . The computing system of  claim 31 , wherein the electronic file system comprising a file server configured to communicate with a client, the client configured to request access to data and upload data to the file server. 
     
     
         33 . The computing system of  claim 32 , wherein the DLP policy instance is implemented for a plurality of electronic file systems, each electronic file system comprising one or more file servers, each file server configured to communicate with a plurality of clients. 
     
     
         34 . The computing system of  claim 33 , wherein the DLP policy template comprises a set of template component fields and is generic to the plurality of electronic file systems, wherein the instructions configure the computing system to:
 transform the generic DLP policy template into a first DLP policy instance that is specific to a first electronic file system by parameterizing the set of template component fields based on a first file system characteristic representing operation of the first electronic file system; and   transform the generic DLP policy template into a second DLP policy instance that is specific to a second electronic file system by parameterizing the set of template component fields based on a second file system characteristic representing operation of the second electronic file system.   
     
     
         35 . The computing system of  claim 34 , wherein the first electronic file system is configured to provide a first service that is different than a second service provided by the second electronic file system. 
     
     
         36 . The computing system of  claim 31 , wherein creating a DLP policy template comprises:
 creating a set of policy template operations, each policy template operation configured to operate upon the DLP policy template.   
     
     
         37 . The computing system of  claim 36 , wherein each policy template operation comprises at least one of:
 an install operation, a remove operation, an import operation, an export operation, a query operation, or a delete operation.   
     
     
         38 . The computing system of  claim 31 , wherein creating a main DLP policy object comprises:
 creating a set of main DLP policy object operations, each DLP policy object operation configured to act upon the DLP policy object.   
     
     
         39 . The computing system of  claim 38 , wherein at least one of the main DLP policy object operations comprises at least one of: creating a new policy object, creating a new state change, editing a state change, or deleting a state change. 
     
     
         40 . A hardware computer-readable storage medium storing computer-executable instructions that, when executed by a computer processor, cause the computer processor to:
 identify a DLP policy template configured to install a data loss prevention (DLP) policy instance for an electronic file system;   create a DLP policy template definition that defines a property to be mapped to a deployment value at a time the DLP policy template is used to create the DLP policy instance;   create a main DLP policy object derivable from the DLP policy template definition and configured to track shared metadata and state of the DLP policy instance;   create a policy rule object defining a policy directive as a match condition and an action derivable from the main DLP policy object; and   create a data classification rule object defining electronic data associated with the electronic file system to which the policy rule object is applied.

Join the waitlist — get patent alerts

Track US2019354691A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.