Best practice: Tuning your environment
- As a best practice, start with assigning the default BDE policy to devices and monitor the alerts prior to enabling automated responses. During this observation period, identify any alerts triggered by legitimate business applications and then add exceptions for them so that business continuity can be maintained when you enable automated responses. You can easily add exceptions from the Alerts view using theActionsmenu.
- Continue to monitor and review all alerts withHighseverity to determine if additional exceptions are required to remove unwanted alerts. You can apply filters in theAlertsscreen to quickly find these alerts. For example, click theProductcolumn heading, and then filter foralerts. By default, the alerts with the highest severity are displayed at the top of the filter results.CylanceOPTICS
- After the recommended observation period of seven to ten days has passed without any alerts triggered by legitimate business applications and no unwanted alerts, you are ready to enable automated responses and start enforcement.
- If you want to enable automated responses for a detection technique, set theAutomated response severitysetting toHigh only. For the remediation actions, addDisplay Desktop Notification,Log Off Remote UsersandTerminate Process Tree.
- To start enforcement, edit the device policy to change the BDE policy operating mode fromAlert onlytoFull enforcement.