Kaspersky Embedded Systems Security 3.4 for Windows

Viewing Device Control rule properties

To view the properties of a Device Control rule:

  1. Go to the Device Control settings in the policy.
  2. On the General tab, click Rules list.

    The Device Control rules window opens.

  3. Double-click a rule name to display its properties.

    The Rule properties window appears.

    Properties of Device Control rules

    Property

    Description

    Apply rule

    Use this option to enable or disable the rule application.

    Manufacturer (VID)

    You can specify the device vendor's full VID or use the * character as a mask. The * character is used to identify any manufacturer.

    If the Use mask check box is selected for the Manufacturer (VID) field, the data from the field with the selected check box is replaced with the * character and is not considered when the rule is applied.

    Controller type (PID)

    You can specify the controller's full PID or use the * character as a mask. The * character is used to indicate any type of controller.

    If the Use mask check box is selected for the Controller type (PID) field, the data from the field with the selected check box is replaced with the * character and is not considered when the rule is applied.

    Serial number

    You can specify the full serial number of the device, or use the * or ? characters as a mask.
    An * (asterisk) denotes any sequence of characters, including an empty sequence.
    A ? (question mark) denotes a single character in a sequence.

    If the Use mask check box is selected for the Serial number field, the data from the field with the selected check box is replaced with the * character and is not considered when the rule is applied.

    If you selected the Use a mask option, but do not enter any characters in the Serial number field, then save the settings and close the window, the application applies * as a mask for the Serial number property and does not consider the field when the rule is applied.

    Device instance path

    Identifier of the connected device.
    The application does not use the field for device control.

    Friendly name

    Device name set by the manufacturer.
    The application does not use the field for device control.

    User or group of users

    You can specify a user account or a group of users with access to the external devices described in this rule:

    • using Active Directory Domain Services
    • using the list of users and user groups of the Administration Server
    • by adding manually.

    The operating system displays all connected external devices. You can access only those external devices that you have access permission for.

    Description

    If necessary, add additional information about the Device Control rule to this field. For example, specify devices covered by the rule.