DLP Violations Policy
Learn how the multi-channel DLP aggregation policy correlates data loss prevention
violations across all channels to identify risky user behavior.
| Where Can I Use This? | What Do I Need? |
|
|
Or any of the following licenses that include the Data Security license:
|
The DLP Violations policy is a static policy that aggregates data loss prevention (DLP)
incidents across all available channels to holistically measure user behavior against
actual DLP violations. By correlating violations across multiple enforcement points at
the user level, this policy identifies patterns of risky behavior that individual channel
alerts might miss in isolation.
Monitored Channels
The policy ingests DLP violations from the following 6 channels:
- Email DLP
- Endpoint DLP
- NGFW
- Prisma® Access
- Prisma® Access Browser
- SaaS API
Threshold and Incident Creation
When a user exceeds the configured threshold of DLP violations (default: 5
medium/high/critical incidents across all monitored channels per day per user), the
platform creates a Behavior Threats incident. This BA incident aggregates the individual
DLP violations and provides a drill-down view listing all contributing DLP incidents
with direct links to the Unified Incident Manager (UIM) for further investigation.
Risk Score Impact
The DLP Violations policy participates in the risk score calculation based on its
assigned
policy weight. The incident event description includes the application, data
profile, action, channel, policy type, and destination to provide full context for each
violation.
Configurable Parameters
You can configure the following parameters for this policy:
| Parameter | Description |
| Name | DLP violations across channels. |
| Description | Aggregates DLP incidents across Endpoint, NGFW, Email, Prisma Access,
SaaS API, and Browser. Triggers a BA incident if a user exceeds a
high-frequency violation threshold. |
| Severity | The severity level assigned to the resulting BA incident when
triggered (Low, Medium, High, or Critical). |
| Enable Policy | A toggle to turn the policy on or off. |
| Users to Exclude | Specific users or user groups to bypass this policy. |
| DLP Channels | Select which of the 6 channels to monitor. |
| Severity Filter | Select which underlying DLP incident severities count toward the
threshold (Critical, High, Medium). |
| Enforcement Action Filter | Determine whether Alert, Block, Encrypt, Forward to Admin, Forward
to Manager, Monitor, Quarantine, Others count toward the
threshold. |
| DLP Incident Threshold | The number of individual DLP violations a user must trigger within a
day to generate a BA incident (default: 5). |
| Data Profiles (Included) | Specific data profiles to include. For example, Bulk CCN, CCPA, and
so on. By default all data profiles are included. Select the data
profiles from the drop down to customize your selection. |
| Notify via Email | A toggle to trigger an immediate email notification to admins when the
threshold is breached. |
Manage DLP Policies (part of static policies)
- Select .
- To enable or disable a DLP policy, select its toggle.
- Use the Edit option under the Action menu to edit the DLP policy.
After modifying the following as per your need, select .
You cannot edit the name and
description of the DLP policy.
- Severity
- Enable or disable the policy.
- Scope of the policy: Users to exclude, DLP channels, DLP severity,
Enforcement Action, DLP Incident Threshold, Data Profiles
- Set policy actions: Notify via email.