How to Configure Your Label Policy
Complete a label policy assessment. To determine which labels to create, see Configuring Labels on an Oracle Solaris System.
You must be assigned the Object Label Management rights profile or be in the root
role. For more information, see Using Your Assigned Administrative Rights in Securing Users and Processes in Oracle Solaris 11.4.
Defining a label policy is the first step in data loss protection. Later you will assign labels to file systems, and assign selected users a clearance that is higher than the default to view sensitive files.
This procedure uses the following configuration parameters:
-
Encodings file =
site-enc
-
Minimum label (Lower bound of user labels) = Public
-
Next higher classification = Confidential
-
Confidential label hierarchy = Confidential Internal Use Only, Confidential Restricted, Confidential Highly Restricted
-
Clearance (Upper bound of user labels) = Confidential Internal Use Only
Next Steps
If you have disjoint labels to define, you can do so now. For an example, see Example - Label Encodings File With Reused Compartment Bits and the labelcfg
(8) man page.