Data Loss Prevention Incident Response Integration with Proofpoint
The Proofpoint DLP integration supports the ingestion of Data Loss Prevention incidents created on the Proofpoint Data Loss Prevention deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.
Request apps on the Store
Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
Overview and key features
The Proofpoint DLP integration helps companies to track the usage and movement of sensitive data on various platforms.
This integration includes the following key features:
- Multiple profile creation for different Proofpoint endpoints.
- Automating the creation of DLP incidents.
- Mapping of the Proofpoint DLP incident state field to DLP incident state field.
- Filtering of Proofpoint DLP incidents.
- Ingestion of incidents in your ServiceNow instance as soon as the incidents are created on Proofpoint DLP tenant.
- Proofpoint DLP integration supports both endpoints and email type of incidents.
- Automatic updates for the Proofpoint DLP incident status and comments for DLP incident creation, and for state change and closure on ServiceNow side.
Learn about this integration
| Document identifier | Document title |
|---|---|
| Proofpoint product documentation website | Proofpoint product documentation |
| ServiceNow® product documentation website | ServiceNow Product Documentation website |
- Getting started with Proofpoint integration for Data Loss Prevention
The Proofpoint DLP integration supports the ingestion of Data Loss Prevention incidents created on the Proofpoint Data Loss Prevention tenant. After ingestion, the incident management functionalities that remediate the DLP incidents will be used. - Install and configure the Proofpoint integration for Data Loss Prevention
Install and configure the Proofpoint DLP integration from the ServiceNow® Store on your ServiceNow AI Platform instance. Start investigating DLP incidents using the Proofpoint DLP incident data. - Create an Application in Proofpoint and Obtain Client Credentials
Create an Application in Proofpoint and configure the required settings to obtain client credentials. These credentials enable secure access to Proofpoint's API for seamless integration and automation. - Create a Profile for Proofpoint DLP integration
Create an incident profile in your ServiceNow AI Platform instance. Determine the Proofpoint DLP incidents that are suitable for creating DLP incidents. - Map Proofpoint DLP incidents status with ServiceNow incident status
Synchronize the status of the DLP incidents ingested on your ServiceNow instance and DLP incidents of the Proofpoint. Map the ServiceNow Incident status with the Proofpoint Incident status. - Configure Proofpoint DLP integration settings
Modify the Proofpoint DLP integration default system properties. - Domain Separation in Proofpoint DLP integration
Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
Parent Topic:DLP integrations
Related topics
Symantec Integration for Data Loss Prevention Incident Response
Data Loss Prevention Incident Response Integration with Netskope
Internet Content Adaption Protocol (ICAP) integration for DLP IR