Data Loss Prevention Incident Response Analyst Workspace
Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
The DLP workspace consists of a home page with dashboards, list views, and form views that let you monitor DLP incidents.
Review and assign your DLP incidents
Access the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace so that you can review the DLP incidents and assign or resolve them. You can track trends on incidents by severity, top offenders, incidents by scan source, and incidents by policy.
Before you begin
- sn_dlir.analyst - Edit and view DLP incidents.
- sn_dlir.analyst_read and sn_dlir.read - View DLP Incidents.
Procedure
Preview evidence files
Preview Data Loss Prevention Incident Response evidence files in the DLP IR Analyst workspace.
Before you begin
Role required: sn_dlir.analyst
Procedure
Playbook for Data Loss Prevention Incident Response
A Data Loss Prevention Incident Response Playbook is a step-by-step guide for addressing and mitigating data loss incidents, which can include unauthorized exposures, leaks, or breaches of sensitive information that can compromise your organization’s security.
The following image shows the sample Playbooks available for DLP IR.
The following table lists the activities and stages available for creating a DLP Playbook. For more information, see Add a DLP Playbook:
| Activity | Description |
|---|---|
| Detection | Identify and confirm unauthorized access or exposure of sensitive data. |
| Containment | Isolate affected systems or users to prevent further data leakage or unauthorized access. |
| Investigation | Investigate the breach to understand how it occurred, what data was affected, and the potential impact. |
| Notification | Notify internal teams, external stakeholders, and regulatory bodies as required by law or policy. |
| Remediation | Apply corrective measures to address vulnerabilities, update policies, and prevent future breaches. |
| Recovery | Restore systems from secure backups and validate the integrity of data post-incident. |
| Post-Incident Review | Analyze the incident to identify root causes, improve security controls, and strengthen policies. |
The following figure shows the workflow of activities and stages involved in the creation of the Sensitive Data Breach Playbook. Playbook steps vary depending on the workflow.
Add a DLP Playbook
Add a Playbook in the Data Loss Prevention Incident Response Analyst workspace that can act as a guide for addressing and mitigating data loss incidents that can compromise your organization’s security.
Before you begin
Role required: sn_dlir.analyst - Add or view Playbooks in the DLP workspace.
Procedure
Cancel a DLP Playbook
Cancel a Data Loss Prevention Incident Response Playbook to stop a business flow when it is no longer valid.
Before you begin
Role required: sn_dlir.admin.
Procedure
- Navigate to .
- Open any DLP incident.
- Navigate to the Playbooks tab.
-
In the header of the Playbook that you want to cancel, select the Playbook actions icon (
) and then select Cancel Playbook.
- Provide a reason for canceling the Playbook.
- Select Cancel Playbook.
Result
A banner appears below the Playbook header confirming that the Playbook has been canceled.
View archived DLP incidents
Use the DLP Analyst workspace to view or reactivate the archived DLP incidents.
Before you begin
- sn_dlir.analyst
- sn_dlir.analyst_read and sn_dlir.read