Help Center

Third-party software Contact us

Incident Management

Incident Management console

The Incident Management console is a centralized interface used to monitor, track, investigate, and resolve security incidents triggered by policy violations. It is designed to provide administrators with a single unified view of all incidents raised across DataSecurity Plus in real time.

When a policy is violated, an incident is automatically generated and logged in the console. This ensures that all security-relevant events are captured and acted upon promptly. At present, the console receives incidents exclusively from the DLP Policy Management module. Support for additional sources will be added in subsequent releases.

The incident response workflow:

  • An event meets the conditions defined in a preconfigured DLP policy.
  • The response specified in the policy—Block, Warn, or Allow—is executed.
  • The event is automatically recorded as an incident in the Incident Management console.
  • The administrator reviews the incident details and assigns it to an appropriate technician for investigation.
  • The assigned technician analyzes audit logs, event context, and user activity to determine the cause and intent.
  • Once the investigation is complete and necessary actions are taken, the incident is marked as resolved.

A sample scenario

An user attempts to send an Outlook email containing Social Security numbers to a recipient outside the pre-approved list. This action violates a preconfigured DLP policy. Now:

  • DataSecurity Plus blocks this event and displays an in-product notification prompt saying, This action has been blocked as per the organization's data protection policy.
  • DataSecurity Plus automatically creates an incident in the Incident Management console.
  • The administrator reviews the incident to confirm that no sensitive data was exposed and assigns it to a technician for further investigation.
  • The technician examines event details and evaluates the user's intent:
    • If the action is legitimate, the technician should update the DLP policy by adding exclusions or refining its conditions.
    • If the action is unauthorized or risky, the technician strengthens the policy or takes corrective action.
  • Once addressed, the incident is marked as resolved.

How to view incidents

To check incident raised:

  • Open the DataSecurity Plus web console. Choose Incident Management from the application drop-down at the top or from the Apps page.
  • The Security Incidents page lists all incidents raised within ManageEngine DataSecurity Plus.
  • Use the status filter at the top to view incidents by status—Open, In Progress, Dismissed, or Resolved—across different time periods.

Each incident entry includes the following details:

  • User who triggered the event
  • Device from which the event was triggered
  • Communication channel across which the event was triggered
  • Event time
  • Severity of the incident
  • Type of security threat
  • Incident status
  • Technician the incident is assigned to

How to review and manage incidents

  • Open the DataSecurity Plus web console. Choose Incident Management from the application drop-down at the top or from the Apps page.
  • On the Security Incidents page, hover over the desired incident and click View Details.
  • On the Incident Details page, administrators and technician can review and update the following fields as needed:
    • Incident name: Edit the name to reflect the nature of the incident.
    • Description: Add or update a description to provide more context for the investigation.
    • Status: Update the incident status to Open, In Progress, Dismissed, or Resolved as the investigation progresses.
    • Severity: Adjust the severity level if required.
    • Assignee: Assign the incident to the appropriate technician for investigation.
    • Comment: Add comments to document findings, actions taken, or any other relevant notes.

For further investigation, use the tabs within the Security Incident page to scrutinize details such as:

Event Details

Reviews the specific event that triggered the incident, including basic information such as event time, triggered policy name, and the user who triggered it along with additional information about the exit point. For example, if the exit point is email, then this will include the email's body content, subject line, sender address, and number of attachments.

Data Identifiers Matched

Lists the specific data identifiers matched during the event along with the number of matches found for each identifier.

Timeline

Displays a chronological audit trail of all actions taken on the incident, including when it was created and by whom, and any subsequent updates made to it.

Don't see what you're looking for?

  • Visit our community

    Post your questions in the forum.

     
  • Request additional resources

    Send us your requirements.