Configuring the User Risk Response Condition

Create a response rule that executes based on the user risk score.
You can create a user risk response condition when user risk detection is enabled.
You can configure the response rule condition to execute based on various user risk scenarios. For example, you can create a response rule to block a sensitive file transmission with the user risk score is greater than 80 and the content violates a PII policy.
  1. Click
    Manage > Policies > Response Rules
    , click
    Add Response Rule
    , and select
    Automated Response
    .
  2. Configure a response rule at the
    Configure Response Rule
    screen.
    For more information, see Configuring response rules.
  3. Select the
    User Risk Score
    condition from the
    Conditions
    list.
  4. Select the user risk requirements to trigger actions. See the following table for a description of the condition parameters.
    Parameter
    Input
    Description
    Matches Exactly
    User risk number
    Triggers a response rule action if the user risk score matches.
    Is Greater Than
    User risk number
    Triggers a response rule action if the user risk score is exceeded.
    Is Greater Than or Equals
    User risk number
    Triggers a response rule action if the user risk score is met or exceeded.
    Is Between
    User risk number
    Triggers a response rule action when the user risk score is within the range of numbers specified.
    Is Less Than
    User-specified number
    Triggers a response rule action if the user risk score is less than the specified number.
    Is Less Than or Equals
    User-specified number
    Triggers a response rule action when the user risk score is equal to or less than the specified number.