Symantec Integration for Data Loss Prevention Incident Response
-
- UpdatedNov 5, 2024
- 2 minutes to read
- Xanadu
- Security Operations
The Symantec DLP integration supports the ingestion of Data Loss Prevention Incident Response incidents created on the Symantec Data Loss Prevention Incident Response deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.
Request apps on the Store
Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
Overview and key features
The Symantec DLP integration helps companies to track the usage and movement of sensitive data on various platforms.
- Ability to create multiple integration profiles for different Symantec API endpoints.
- Scheduled ingestion of DLP incidents from Symantec into your ServiceNow instance.
- Ability to apply API filters to retrieve the incidents that match the filter criteria and also specify the filter for Symantec DLP incidents that are required to be imported.
- Ability to store the evidence file internally in the ServiceNow instance.
- Ability to map the DLP incident states in your ServiceNow instance to DLP incident states in Symantec.
- Automatically update incident status in Symantec when the state changes in your ServiceNow instance.
- Ability to customize and define the severity mapping between Symantec DLP incidents with ServiceNow incidents.
- Ability to download the evidence file for Symantec incidents from directly Symantec server or from internal ServiceNow storage.
- Supports smart response rules from ServiceNow.
To learn more about the integration, see the Symantec product documentation.
Related Content
- Data Loss Prevention Incident Response Integration with Proofpoint
The Proofpoint DLP integration supports the ingestion of Data Loss Prevention incidents created on the Proofpoint Data Loss Prevention deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.
- Data Loss Prevention Incident Response Integration with Netskope
The Netskope DLP integration supports the ingestion of Data Loss Prevention incidents created on the Netskope Data Loss Prevention deployment. Netskope DLP helps companies to track the usage and movement of sensitive data on various platforms.
- Internet Content Adaption Protocol (ICAP) integration for DLP IR
The Internet Content Adaption Protocol (ICAP) DLP integration supports the ingestion of Data Loss Prevention Incident Response alerts, allows the fetching of match content, and evidence files from Amazon S3 created on the ICAP supported Data Loss Prevention Incident Response deployment.
- Data Loss Prevention Incident Response with Microsoft
The Data Loss Prevention Incident Response with Microsoft provides a core framework to import Data Loss Prevention (DLP) incidents from multiple sources such as Microsoft preview apps (Microsoft Teams, Exchange Online, SharePoint Online, OneDrive for Business) and other event types as well. Endpoint devices enable remediation workflow involving end users, managers, and DLP operations team with automated incident assignment and escalations.