logo

NJP

Data Loss Prevention Incident Response Demonstration Video

Import · Mar 24, 2022 · video

organizations have long struggled to keep up with the overwhelming amount of data loss prevention incidents they have to manage disparate products across their infrastructure make managing the incidents difficult to track in a timely fashion and can be even more frustrating for end users and their managers dlp incident response part of servicenow security operations gives us the power to integrate with data loss prevention products to import incidents from multiple sources including endpoint network email and cloud into a single platform then using a remediation workflow we can automatically assign incidents to end users managers and dlp analyst teams with automated incident assignment and escalation all using intuitive easy to use workspaces designed specifically to make managing and reporting this work easy there are four main use cases that dlp incident response helps address first by enabling the api integration with solutions like symantec broadcom dlp we can import incidents for endpoint network cloud and email into servicenow and then invoke dlp incident remediation workflows involving end users or employees managers and dlp analysts dlp incident response also allows dlp administrators the ability to define and filter which incidents will be imported into servicenow based on the requirements of the organization dlp administrators can also configure email templates for coaching and communicating to end users and provides comprehensive reporting on incident trends and when it's needed incidents can be escalated up the chain of command dlp admins can define the escalation criteria for the different types of incidents furthermore dlp analysts can also log into their own workspace to view the state of dlp across their enterprise and respond to different incidents directly when needed finally dlp incident response reduces the burden on the dlp analyst team since many dlp incidents are generated due to the error on the end users part now incidents can be assigned directly to the end users and email templates can be used either as a weekly digest or whenever an incident is discovered with why the incident was generated and how to resolve it let's take a look at the dlp analyst workspace first and then we'll see what the end user workspace looks like the dlp analyst workspace is designed to give the people responsible for managing incidents a holistic view of data loss instruments in their environment it shows dlp analysts a wealth of information including open incidents by severity the top offenders we scroll down we can even see open incidents by policy scan source and more let's drill into one of these categories let's look at the critical open incidents by severity we can see that there's a lot of information available to the dlp analyst including the policy names the state of each individual incident the severity etc if we look at one of these we can see that it shows the state the scan type the source as well as the end user and in this particular case we can see that this particular dlp incident was assigned to the end user automatically based on assignment rules the dlp admin set up now let's switch personas and take on the role of danny watson we're not logged in as danny as we can see in the upper right hand corner we can see a few important details when we log in to the end user workspace we can see the escalated incidents incidents that are assigned to you due the next seven days etc let's go ahead and look at the incidents assigned to you and again we see a lot of useful information for the end user including the policy name of each incident the severity scan source and when appropriate the file location i'm going to scroll down and find the same incident that we were looking at earlier a lot of the same information is available to the end user that the dlp analysts saw such as the scan type source end user it's worth noting that danny can upload attachments if needed for example if danny received an email exception from management they can attach an email right here the end user can also take direct action such as reporting this as a false positive reporting that it's the wrong owner or submitting a response let's go ahead and see what different responses are available to us now these responses were set up by the dlp administrator ahead of time this is fully customizable so in this particular case we can say that we've deleted the content we can say this is required for a business process like in the example we had just talked about using the attached file or we can say we've deleted the file once that's done we can enter in some comments and click submit that was a brief look at the new dlp incident response for servicenow security operations if you'd like to learn more please visit us at www.servicenow.com sec dash ops thank you

View original source

https://www.youtube.com/watch?v=HwO_jvhXYls