Policy & Incident Management
Data privacy compliance is a continuous process of assessing risk, establishing and managing policies, detecting incidents, determining root causes, remediating them and tracking trends over time. Code Green Networks provides a rich set of capabilities to facilitate easy management of data policies and highly customizable, detailed incident management and reporting.
Policy Management
Code Green Networks provides robust policy management functions that allow content authorities and administrators to customize data security policies so that customer data, personal or confidential information is protected and acceptable use and best practice policies are enforced. A range of customizable, predefined policy templates are also included and allow content authorities to quickly define and roll out policies that meet their organization’s objectives.
Policies are assembled from registered content, context constraints and actions. Context constraints include file filters, source and destination addresses and protocol constraints. The policy can also be designed to apply to inbound or outbound traffic or both. Exceptions can also be defined and can include content exceptions, called “GreenList,” that help to identify company boilerplates to eliminate false positives from commonly used text.
Policy actions determine how a policy will respond when its conditions are met. Content carried on network traffic is inspected and compared to policies for matches in real time. When the policy conditions are met, the policy creates incidents and can assign them to individual reviewers or groups to be managed in a workflow. Incident actions can also include encrypting email or redirecting it for further processing, providing great flexibility in addressing your particular business process requirements.
Incident Management
Once an incident is generated, workflow begins and allows the incident to be resolved. By defining workflow procedures, organizations can apply different levels of policy enforcement allowing actions such as notification, copy retention and logging to be initiated. Incident management includes a powerful role-based access control mechanism supporting your business processes and enforcing strict confidentiality in managing content based security events.
Reporting
Supporting the Code Green Networks attention to usability is an on-board reporting system that comes equipped with a range of predefined reports as well as a simple to use interface for defining custom reports that can be printed or exported. These combine to enable management to easily review key compliance metrics.
Detailed reporting allows charts and tables to be created that group incidents or subsets of incidents into specified categories. Exploratory data analysis allows for drilling down to one item in a category with further analysis. For example, routine reports might show that there were a large number of transactions leaving the network that contained credit card numbers, and further analysis might show that these transactions were coming from a single employee.

