DLP Violations Policy
Focus
Focus
SaaS Security

DLP Violations Policy

Table of Contents

DLP Violations Policy

Learn how the multi-channel DLP aggregation policy correlates data loss prevention violations across all channels to identify risky user behavior.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
The DLP Violations policy is a static policy that aggregates data loss prevention (DLP) incidents across all available channels to holistically measure user behavior against actual DLP violations. By correlating violations across multiple enforcement points at the user level, this policy identifies patterns of risky behavior that individual channel alerts might miss in isolation.
Monitored Channels
The policy ingests DLP violations from the following 6 channels:
  • Email DLP
  • Endpoint DLP
  • NGFW
  • Prisma® Access
  • Prisma® Access Browser
  • SaaS API
Threshold and Incident Creation
When a user exceeds the configured threshold of DLP violations (default: 5 medium/high/critical incidents across all monitored channels per day per user), the platform creates a Behavior Threats incident. This BA incident aggregates the individual DLP violations and provides a drill-down view listing all contributing DLP incidents with direct links to the Unified Incident Manager (UIM) for further investigation.
Risk Score Impact
The DLP Violations policy participates in the risk score calculation based on its assigned policy weight. The incident event description includes the application, data profile, action, channel, policy type, and destination to provide full context for each violation.
Configurable Parameters
You can configure the following parameters for this policy:
ParameterDescription
NameDLP violations across channels.
DescriptionAggregates DLP incidents across Endpoint, NGFW, Email, Prisma Access, SaaS API, and Browser. Triggers a BA incident if a user exceeds a high-frequency violation threshold.
SeverityThe severity level assigned to the resulting BA incident when triggered (Low, Medium, High, or Critical).
Enable PolicyA toggle to turn the policy on or off.
Users to ExcludeSpecific users or user groups to bypass this policy.
DLP ChannelsSelect which of the 6 channels to monitor.
Severity FilterSelect which underlying DLP incident severities count toward the threshold (Critical, High, Medium).
Enforcement Action FilterDetermine whether Alert, Block, Encrypt, Forward to Admin, Forward to Manager, Monitor, Quarantine, Others count toward the threshold.
DLP Incident ThresholdThe number of individual DLP violations a user must trigger within a day to generate a BA incident (default: 5).
Data Profiles (Included)Specific data profiles to include. For example, Bulk CCN, CCPA, and so on. By default all data profiles are included. Select the data profiles from the drop down to customize your selection.
Notify via EmailA toggle to trigger an immediate email notification to admins when the threshold is breached.
Manage DLP Policies (part of static policies)
  1. Select Behavior ThreatsPoliciesStaticDLP Violations.
  2. To enable or disable a DLP policy, select its toggle.
  3. Use the Edit option under the Action menu to edit the DLP policy. After modifying the following as per your need, select NextSave.
    You cannot edit the name and description of the DLP policy.
    • Severity
    • Enable or disable the policy.
    • Scope of the policy: Users to exclude, DLP channels, DLP severity, Enforcement Action, DLP Incident Threshold, Data Profiles
    • Set policy actions: Notify via email.