Enforce data loss prevention policies across Cisco Webex Teams
Unified DLP Reporting and Remediation
McAfee reports on DLP violations in Cisco Webex Teams and other cloud services in a unified interface with highlighted excerpts revealing the exact content that triggered the DLP policy. During review, if a file does not violate a policy, the reviewer can rollback the remediation action to restore the file and/or its sharing permissions. Quarantined files are stored in a secure account within Cisco Webex Teams, not in McAfee’s platform, for added security.
Deep Integration with On-Premises DLP Solutions
With McAfee you have the option of leveraging our best-in-class DLP engine or the policies in your existing on-premises solution such as McAfee DLP, Symantec DLP, Forcepoint DLP, and more. McAfee optionally performs a first-pass content inspection, brokers inspection by the on-premises solution, acts as an enforcement point to apply policies to data in the cloud, and registers enforcement in the on-premises solution that maintains the policy.
McAfee automatically constructs a behavior model with dynamic and continuously updated thresholds for each user and team to identify activity indicative of insider threat, whether the threat is accidental or malicious. Using Guided Learning, you can fine tune the detection of cloud-based threats by providing feedback to the system that is incorporated into models of user behavior to more accurately detect future threats.
McAfee detects compromised account activity in Cisco Webex Teams based on brute-force login attempts, logins from new and untrusted locations for a specific user, and consecutive login attempts from two locations in a time period that implies impossible travel, even if the two logins occur across two cloud services. Darknet Intelligence reveals user accounts for sale online that are at risk of compromise.
Make Cisco Webex Teams your corporate standard
McAfee identifies collaboration solutions that employees use in place of the corporate standard, Cisco Webex Teams, and provides a risk rating for each service. Using McAfee, you can enforce risk-based governance controls and coach users to Cisco Webex Teams to improve collaboration while also reducing cost and risk.
Shadow IT Discovery
Discovers all shadow IT cloud services employees are using in place of the corporate standard, Cisco Webex Teams.
Identifies all users and groups accessing Cisco Webex Teams and reveals which users are accessing sensitive data.
Cloud Data Loss Prevention
Enforces DLP policies based on data identifiers, keywords, and structured/unstructured fingerprints across data at rest and uploaded or shared in real time.
Structured Data Fingerprinting
Fingerprints billions of unique values stored in enterprise databases and systems of record and supports exact match detection of each value.
Provides coach user, notify administrator, block, and delete options and enables tiered response based on severity.
Displays an excerpt with content that triggered a DLP violation. Enterprises, not MVISION, store excerpts, meeting stringent privacy requirements..
Cisco Webex Teams SOC
Delivers a threat dashboard and incident-response workflow to review and remediate insider threats, privileged user threats, and compromised accounts.
User Behavior Analytics
Automatically builds a self-learning model based on multiple heuristics and identifies patterns of activity indicative of a malicious or negligent insider threat.
Provides human input to machine learning models with real-time preview showing the impact of a sensitivity change on anomalies detected by the system.
MVISION Enterprise Connector
Facilitates integration with firewalls, proxies, SIEMs, directory services via LDAP, on-premises DLP, HSMs, and EMM/MDM solutions and tokenizes sensitive data.
Integration with SIEMs
Collects log files from SIEMs and provides the ability to report on incidents and events from MVISION in SIEM solutions via syslog and API integration.
Coaching and Enforcement
Displays just-in-time coaching messages guiding users from unapproved services to Cisco Webex Teams and enforces granular policies such as read-only access.
Discovers and groups users from directory services and Cisco Webex Teams. User groups can be leveraged for analytics and policy enforcement.
Pre-Built DLP Templates
Provides out-of-the-box DLP templates and a broad range of international data identifiers to help identify sensitive content such as PII, PHI, or IP.
Unstructured Data Fingerprinting
Fingerprints sensitive files and detects exact match and partial or derivative matches with a policy-defined threshold for percentage similarity to the original.
Policy Violation Management
Offers a unified interface to review DLP violations, take manual action, and rollback an automatic remediation action to restore a file.
Closed-Loop Policy Enforcement
Optionally leverages policies in on-premises DLP systems, enforces policies, and registers enforcement actions in the DLP system where the policy is managed.
Cloud Activity Monitoring
Provides a comprehensive audit trail of all user and administrator activities to support post-incident investigations and forensics.
Account Compromise Analytics
Analyzes login attempts to identify impossible cross- region access, brute-force attacks, and untrusted locations indicative of compromised accounts.
MVISION Cloud Connector
Connects to cloud services via cloud provider APIs to provide visibility and enforce security and compliance policies for all users and cloud-to-cloud activity.
Integration with On-Premises DLP
Provides integration and closed-loop remediation with existing on-premises DLP solutions such as McAfee, Symantec, and Forcepoint.