Fortinet white logo
Fortinet white logo

FortiDLP Administration Guide

Terminology

Terminology

FortiDLP documentation uses the following terminology.

Term

Definition

Operator

Either a:

  • system administrator who maintains a FortiDLP deployment, or

  • security analyst, Fortinet cyber analyst, or other person who uses FortiDLP to protect an organization's computer networks, systems, and data.

User

An employee, contractor, partner, or other person who uses a computer that the FortiDLP Agent monitors.

Managed node

A computer or server that the FortiDLP Agent monitors.

External host

An unidentified device that communicates with a managed node.

Entity

A user, managed node, or external host.

Event

An activity occurring on a managed node.

Example

If web monitoring is enabled, a browser event is recorded each time a user visits a URL, uploads a file, and downloads a file.

Detection

A suspicious activity occurring on a managed node that:

  • deviates from the norm based on historical data (behavioral analytics detection)

  • breaches corporate security policies (policy detection), or

  • indicates node inactivity (Agent offline detection).

Example

A policy detection could indicate when a user attempts to copy a sensitive file to a USB storage device.

Incident

A group of policy detections that have the same root cause or policy name, depending on configuration.

Example

An incident could comprise detections where one or multiple users attempt to upload sensitive files to the same file share website.

Terminology

Terminology

FortiDLP documentation uses the following terminology.

Term

Definition

Operator

Either a:

  • system administrator who maintains a FortiDLP deployment, or

  • security analyst, Fortinet cyber analyst, or other person who uses FortiDLP to protect an organization's computer networks, systems, and data.

User

An employee, contractor, partner, or other person who uses a computer that the FortiDLP Agent monitors.

Managed node

A computer or server that the FortiDLP Agent monitors.

External host

An unidentified device that communicates with a managed node.

Entity

A user, managed node, or external host.

Event

An activity occurring on a managed node.

Example

If web monitoring is enabled, a browser event is recorded each time a user visits a URL, uploads a file, and downloads a file.

Detection

A suspicious activity occurring on a managed node that:

  • deviates from the norm based on historical data (behavioral analytics detection)

  • breaches corporate security policies (policy detection), or

  • indicates node inactivity (Agent offline detection).

Example

A policy detection could indicate when a user attempts to copy a sensitive file to a USB storage device.

Incident

A group of policy detections that have the same root cause or policy name, depending on configuration.

Example

An incident could comprise detections where one or multiple users attempt to upload sensitive files to the same file share website.