Processing CASB Alerts
Audience: Security Operations and Data Protection teams.
Purpose: Review and process CASB alerts for data exposure incidents.
Overview
CASB alerts are triggered when users share sensitive data via cloud applications. This guide covers the alert review and triage process.
Accessing the Console
- Navigate to the CASB Analytics page
- Log in with your NETID-admin account
Reviewing Alerts
Step 1: Navigate to Explorations
- From the dashboard, click See all explorations
- Select WeeklyPublicSharingAlerts
Activity Indicators
Dashes underneath "Activity" descriptions indicate the number of DLP rules triggered by the file action. These consolidate when alerts share the same status.
Step 2: Filter New Alerts
- Click the three dots (⋮) next to the STATUS dropdown
- Select Filter by New
Step 3: Review Individual Alert
- Click any dash under the file ACTIVITY
- Detail pane opens on the right
Step 4: Claim the Alert
- Change STATUS to In Progress
- Click under ASSIGNEE and select your name
Step 5: Review Triggered Rules
- Scroll to bottom of detail pane
- Click + to expand rule details
- Review keywords that triggered the alert
Classification Decision
False Positive
If keywords don't represent sensitive data:
- Change STATUS to False Positive
- No further action needed
True Positive (Needs Review)
If keywords may represent sensitive data:
- Change STATUS to On Hold
- Open a ServiceNow ticket (see below)
Opening ServiceNow Ticket
Step 1: Access Form
Open the CASB Detection Form
Step 2: Gather Information
From the CASB detail pane, collect:
| Form Field | Location in CASB |
|---|---|
| NetID | Details → User → expand |
| Details → User → expand | |
| File Name | Details → Website → expand |
| File URL | Details → Website → expand |
| Platform | Details → Website → expand |
| Detection Type | Rule name at top of detail pane |
Step 3: Determine Detection Type
| Rule References | Detection Type |
|---|---|
| HIPAA data | PHI |
| SSN | SSN |
| Credit Card | PCI |
Step 4: Submit
- Complete all fields
- Click Submit
- Confirmation message displays with ticket number