注記
この機能を有効にするには、 Netskope Sales にお問い合わせください。
リアルタイム保護ポリシーにファイルプロファイルを追加する機能は現在ベータ版です。この機能を有効にするには、 Netskopeサポートまたは営業担当者にお問い合わせください。
データ損失防止(DLP)と脅威対策以下の属性に基づいて特定のファイルを許可または除外するためのファイルプロファイル:
| OR | |
| 名前または内線番号 | |
| ファイルの種類 | |
| ファイルハッシュ | |
| オブジェクトID | |
| AND | |
| ファイルサイズ | |
| Protected/Encrypted | |
| センシティブラベル |
ファイルプロファイルごとに複数の属性を設定できます。Netskopeは、属性の種類(ORとAND)に応じて、条件を満たすファイルをスキャンします。例えば、ファイルの種類とファイルハッシュ属性を含むファイルプロファイルを追加すると、Netskopeは指定されたファイルの種類またはファイルハッシュを持つファイルをスキャンします。Netskopeにファイルサイズや、ファイルがパスワードで保護されているか暗号化されているかをスキャンさせることもできます。例えば、ファイルの種類、ファイルハッシュ、ファイルサイズ属性を含むファイルプロファイルを追加すると、Netskopeは指定されたファイルの種類またはファイルハッシュを持ち、設定されたファイルサイズに一致するファイルをスキャンします。
ファイルプロファイルを追加するには:
- Policies > Fileへ移動してください。
- New File Profileをクリックしてください。
- Add File ProfileウィンドウのFile Attributesの下:
- Name or Extensionファイル名は拡張子を含めて、別々の行に入力するか、カンマで区切ってください。また、1行あたり最大2つのワイルドカード(*)文字を使うことができ、ケース感度の有効・無効も可能です。 CSVファイルからファイル名をアップロードするには、 Import from CSVをクリックしてください。
- Add to ListCSVファイル内の既存のエントリに、ファイル名または拡張子を追加します。Replace File : 既存のエントリをCSVファイル内のファイル名または拡張子に置き換えます。
File Typeファイル形式やカテゴリ Select 。 カテゴリを選択すると、デフォルトで全てのファイルタイプが選択されます。クリック
各カテゴリ内の特定のファイルタイプを表示、選択、または選択解除する。Categoriesをクリックするとカテゴリ表示に戻ります。Netskopeは特定のファイル形式ではなくカテゴリを選択することを推奨しており、その方がカバー範囲が広がるためです。サポートされているすべてのファイルの種類とカテゴリの一覧については、 「サポートされているファイルカテゴリとファイルの種類」を参照してください。
注記
この属性はDLPプロファイルでのみサポートされています。
File Hashファイルのハッシュタイプ(SHA-256、MD5など) Select 、ハッシュ値を別々の行に入力してください。 Import from CSVをクリックしてCSVファイルからファイルハッシュをアップロードします(8MB制限):
Add to List :CSVファイル内のファイルハッシュを既存のエントリに追加します。
Replace File : 既存のエントリをCSVファイル内のファイルハッシュに置き換えます。MD5またはSHA-256ファイルハッシュリスト内のすべてのエントリを削除するには、 MoreをクリックしてからRemoveクリックします。
Object IDファイルのオブジェクトIDを入力してください。Import from CSVをクリックしてCSVファイルからオブジェクトIDをアップロードします:
Add to List :CSVファイル内のオブジェクトIDを既存のエントリに追加します。
Replace File : 既存のエントリをCSVファイル内のオブジェクトIDに置き換えます。
File Size: Configure the file size criteria of the file by choosing an operator, entering a size number, and choosing a unit. The file size is an AND attribute.
Protected/Encrypted: Select the type of protection or encryption of the file. The protected/encrypted options are an AND attribute.
File is password-protected: The file is a password-protected ZIP, PDF, or Office document.
File is protected by MIP: Identify if the file is protected by Microsoft Information Protection (MIP).
Encrypted by:
Sanctioned Instance: : Selecting this will check if the content is encrypted using any connected corporate MIP Instance. (An Instance that has been setup on the settings page is treated as a corporate instance)
Unsanctioned Instance: Selecting this will check if the content is encrypted using any MIP Instance (Any instance apart from what is setup is considered as unsanctioned instance)

Sensitivity Label: Sensitivity labels from Microsoft Purview Information Protection let you classify and protect your organization’s data. This section allows you to configure what sensitivity label that Netskope should look for while inspecting the traffic. Workflow for choosing the labels is as below:
Select the Vendor, Instance, and Label setting.
If you would like to detect whether content has a sensitivity label, select the option “Detect object with classification label applied from the selected instance.” Multiple labels can be configured.
If you would like to detect if the content does not have any sensitivity label applied to it, select the option “Detect object with no classification label applied from the selected instance”.
There are no labels that can be selected with Detect object with no classification label applied.

- Name or Extensionファイル名は拡張子を含めて、別々の行に入力するか、カンマで区切ってください。また、1行あたり最大2つのワイルドカード(*)文字を使うことができ、ケース感度の有効・無効も可能です。 CSVファイルからファイル名をアップロードするには、 Import from CSVをクリックしてください。
- Nextをクリックしてください。
- Set Profile以下:
- Profile Nameファイルプロファイルの名前を入力してください。
- Description: (オプション) ファイルプロファイルのデスクリプションを入力します。

- Saveをクリックしてください。
- Apply Changesをクリックしてください。
ファイルプロファイルを追加すると、 DLPまたはマルウェア検出プロファイルを設定する際に、そのプロファイルを選択して、特定のファイルやその属性に基づく動作を許可またはブロックすることができます。
注: Netskope 、MIP 暗号化されたコンテンツの検査が可能です。 これにより、暗号化ファイルが復号化され、ポリシー違反がないか検査されるため、可視性がさらに高まります。 コンテンツdoes not need any configuration changesの復号化に注意してください。インスタンスがセットアップされている場合は、このインスタンスを使用して暗号化されているすべてのコンテンツに対して自動的に復号化が機能するはずです。
Filetypes supported: Netskope 使う Microsoft SDK を統合します。 したがって、NetskopeはMicrosoftがサポートするすべてのファイル形式をサポートします。https://learn.microsoft.com/en-us/information-protection/develop/concept-supported-filetypes
注:この統合機能の一部として、共同編集機能が有効になっている場合のMIPラベルの読み取りもサポートされています。

