Create incident response option rules
Create the incident response option rules that end user or analyst can use while responding to an incident.
시작하기 전에
Role required:
- sn_dlir.admin - Create, edit, and delete.
- sn_dlir.analyst and sn_dlir.analyst_read - View (read-only).
이 태스크 정보
You can configure the type of response that an end user should perform based on the type of DLP incident. The base system DLP Incident Response application provides the following response options for users:
- Assessment Complete
- Deleted Content
- Deleted File
- Encrypted File
- Masked Content
- Report false positive
- Report wrong owner
- Required for Business Process
- Reviewed Entitlements
For example, let's say that an end user reports a DLP incident as a false positive. The state for this incident is then automatically marked as closed because the target state that is configured by you is closed.