logo

NJP

DLP Incident Response integration with ICAP

DLP Incident Response integration with ICAP

by Service-now.com

DLP Incident Response integration with ICAP

0 installs 0 reviews v1.1.3 Scoped Application Free (integration tables[8] not counted) 8 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 2 -2
335 days of no change
2025-05-26 1 +1
128 days of no change
2025-01-17 0 +1

About

An integration between ServiceNow's Data Loss Prevention Incident Response product (DLP-IR) and vendors who provide their DLP alerts information using the Internet Content Adaption Protocol (ICAP).

Key Features

- **Ingestion of DLP Alerts from Amazon S3:**
- Users would be able to configure and schedule the ingestion of DLP alerts from specified Amazon S3 buckets. This includes the capability to perform delta imports to ensure only new or modified data is ingested.

- **Display DLP Alerts in the DLP Workspace:**
- Once alerts are ingested, they should be displayed in the DLP workspace by providing the key details on each alert such as the match content, alert severity, and relevant metadata.

- **Evidence File Download:**
- The system would allow users to download associated evidence files directly from the DLP workspace for further investigation or review.

- **Automation and Response Workflows:**
-  Advanced workflow automation should be available for handling alerts, enabling users to apply automatic responses based on predefined criteria. This might include actions like alert escalation, notifications, or enforcement policies.

- **Advanced response options:**
- These could include remediation actions such as blocking or quarantining sensitive data, or sending out alerts to stakeholders.

- **Dashboards and Data Trends:**
- Users should be able to visualize ingested data in the DLP workspace through dashboards and trend reports. This would help track the number and type of DLP incidents over time, offering insights into potential data loss patterns or vulnerabilities.

Version History (9)
v1.1.3 2026-06-16 17:26:44
Fixed:  Addressed a field name mismatch issue during data ingestion.
v1.1.2 2026-05-05 15:36:51
Fixed:  Resolved the issue of the DLP incident evidence files in .unk format not loading correctly. Fixed a download failure occurring when f...
v1.1.1 2026-01-20 15:08:56
Fixed: Enhanced the Zscaler evidence download handling to work with both the legacy path-based and the new filename-based formats.
v1.1.0 2025-12-11 15:10:19
New: Upgraded all dictionary-level read-only fields to Strict Read-Only, to enhance security and prevent unauthorized changes. This update ensure...
v1.0.20 2025-10-16 15:12:32
Fixed: Fixed issue to ensure execution occurs only after Q entry record updates, preventing creation of DLP incidents without proper metadata.
v1.0.11 2025-06-06 01:53:12
Fixed :  Keyboard focus would exit the profile creation confirmation modal when navigating through the dialog options using the Tab key....
v1.0.10 2025-03-12 12:19:40
Fixed : Fixed download feature and ingestion for nested bucket structure, added support for folder structure within S3 buckets.
v1.0.9 2025-01-30 16:15:52
New : Evidence File Preview with Download Option: Added a preview icon for evidence files in the DLP Workspace. Users can now preview evidence fi...
v1.0.7 2024-12-05 16:04:50
Fixed: Access Control Lists (ACLs) applied to the Data Loss Prevention Incident Response(DLP IR) end-user workspace to regulate and manage user pe...
ID: e12b924ba573421074454fe72149844b · Published: Jun 2026 · Updated: Sep 09, 2026