5.1

Table Of Contents
8 Certain regulations require additional information for vShield Data Security to recognize sensitive data.
If you selected a regulation that monitors Group Insurance Numbers, Patient Identification Numbers,
Medical Record Numbers, Health Plan Beneficiary Numbers, US Bank Account Numbers, Custom
Accounts, or Student identification numbers, specify a regular expression pattern for identifying that data.
NOTE Check the accuracy of the regular expression. Specifying incorrect regular expressions can slow
down the discovery process. For more information on regular expressions, see “Creating Regular
Expressions,” on page 182.
9 Click Finish.
10 If you are updating an existing policy, click Publish Changes to apply it.
Specify Areas Participating in the Policy Scan
By default, your entire vSphere infrastructure is scanned by vShield Data Security. To scan a subset of the
inventory, you can exclude or include security groups. If a resource (cluster, datacenter or virtual machine) is
part of both an excluded and included security group, the exclude list takes precedence and the resource is not
scanned.
vShield special appliances (such as vShield Endpoint and Shield App appliances as well as partner appliances
that leverage vShield Endpoint) are not scanned by vShield Data Security
Prerequisites
You must have been assigned the Security Administrator role.
Procedure
1 In the Policy tab of the Data Security panel, expand Participating Areas.
2 To include a security group in the data security scan, click Change next to Scan the following
infrastructure.
a In the Include Security Groups dialog box, type the name of the security group to be included in the
scan.
b Click Add.
c Click Save.
3 To exclude an existing security group from the data security scan, click Change next to Except for the
following areas.
a In the Exclude Security Groups dialog box, type the name of the security group to be excluded from
the scan.
b Click Add.
c Click Save.
4 If you are updating an existing policy, click Publish Changes to apply it.
Specify File Filters
You can restrict the files that you want to monitor based on size, last modified date, or file extensions.
Prerequisites
You must have been assigned the Security Administrator role.
Procedure
1 In the Policy tab of the Data Security panel, expand Files to scan.
Chapter 15 vShield Data Security Management
VMware, Inc. 179