I need a solution
I am new to Symantec DLP and I am looking for the best way to handle this situation. Our organization would like to detect and modify the headers of emails which contain PII (using EDM). However, we would only want to do this for emails which do not already contain our encryption keywords.
Easy enough, create and EDM policy with an exception for the keywords.
This issue I have is that we would also like to alert on emails that contain PII that already have the keyword as well. Is there anyway to accomplish this without creating two seperate policies with the only exception being the keyword exception? Maybe something like an IF statement?