Policies and alerts
Set up data policies that alert you when sensitive data appears in the wrong systems or record counts look irregular, and trace each violation to its source.
Data policies watch your data sources for data that shouldn't be there. For example, you might want to know if health information appears in your marketing tools, or if a system suddenly holds far fewer records than expected. When a policy is violated, MineOS raises an alert and shows you exactly where the data was found, so you can fix the problem before it becomes an incident.
Before you set up policies, make sure your data sources have data types mapped. Policies are based on data types, so they can only detect what classification has found. See Classification quickstart.
Types of policies
| Policy | What it alerts you to |
|---|---|
| GDPR Special misplacement policy | Special category data, such as health, biometric, religious or political data, found in the data sources you select |
| PII misplacement policy | Personally identifiable information found in the data sources you select |
| PHI misplacement policy | Protected health information found in the data sources you select |
| Irregularity policy | A data type's record count falling outside the range you set |
The data types included in each policy follow the classification frameworks in your inventory settings.
Set up a misplacement policy
- Go to the Policies page.
- Select the policy you want to enable.
- Select the data sources you want to monitor. Choose the systems where this type of data shouldn't appear, for example marketing or collaboration tools for health data.
- Turn on the toggle in the top-right corner.
- Click Save.
Set up an irregularity policy
An irregularity policy alerts you when the number of records for a data type looks unusual, for example when a system that normally holds thousands of customer emails suddenly holds fewer than 100.
- Go to the Policies page and select Irregularity policy.
- Enter your criteria, for example a violation when the record count is lower than 100. [approve: limitation: values between 2 and 10,000]
- Select the data sources to monitor.
- Turn on the toggle in the top-right corner, and click Save.
Irregularity policies only work for data sources scanned by the data classifier, because they rely on record counts. [approve: limitation]
View alerts
Policy violations appear on your Data types page, next to each data type that violates one or more policies.
Trace a violation to its source
For data sources that are integrated and scanned, you can see exactly where the violation comes from.
- On the Data types page, click View next to the data type.
- The dialog lists each object where the data type was found, with a link to it in the source system.
A single link can contain several records, for example one support ticket containing two phone numbers.
Act on alerts
| If you find | Consider |
|---|---|
| Sensitive data in a system that shouldn't hold it | Removing the data at the source, and reviewing how it got there, such as a form field or an integration |
| A legitimate new use of sensitive data | Updating your processing activities and assessments to reflect it, and removing the system from the policy |
| An unexpected drop in records | Checking with the system owner for deletions, migrations or integration issues |
Related articles
- Classification quickstart: map data types across your data sources
- Flagging risks in assessments: record the risk if a violation reveals a wider issue
Updated about 2 hours ago
