Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a Data Loss Prevention Incident Response SLA definition

Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.

Before you begin

Role required:

  • sn_dlir.admin - Create, update, and delete DLP SLA definitions.
  • sn_dlir.analyst.read - Read DLP SLA definitions.

Procedure

  1. Navigate to All > DLP Administration > SLA Definitions.

  2. Create an SLA definition.

    For a description of the field values, see DLP SLA Definition form.

  3. Select Submit.

    Note: Due date rules, escalations and SLA definitions are mutually exclusive. An SLA definition primarily determines when a particular SLA will start to be effective, stop, pause, or be triggered.

Parent Topic:DLP Incident Response Administration

Related topics

DLP default configuration settings

Create end user lookup rules

Create assignment rules

Create incident consolidation rules

Create response due date rules

Create Approval Rules

Create user instructions templates

Create email templates

Create a Data Loss Prevention Incident Response SLA trigger

Create assessments

Configure response option for your DLP incidents

Create incident response option rules

Create age chart configurations

Create user delegate configurations

Create repeat offender identification rules

Create additional incident data fields

DLP SLA Definition form

Configure advanced settings

Monitor DLP Integration Run process

DLP Incident Access Restrictions

DLP Incidents Archival