Nightfall Documentation
  • Data Detection and Response
  • Posture Management
  • Data Exfiltration Prevention
  • Data Encryption
  • Developer APIs
  • Data Classification and Discovery
  • Nightfall Posture Management
  • Nightfall Security Posture Management
  • Nightfall Detection Engine
    • Nightfall Detection Engine
  • Nightfall for Google Drive
    • Installing Nightfall for Google Drive
    • Configuring Integration Alerts
    • Configuring Google Drive Policies
      • Integration
      • Scope
      • Trigger
      • Automated Actions
      • Creating Policy
    • Remediation for Google Drive
    • Posture Management Events Page
Powered by GitBook
On this page
  • Admin Notification and Remediation
  • End-User Notification and Remediation
  • Managing Violations in Nightfall

Was this helpful?

Export as PDF
  1. Nightfall for Google Drive

Remediation for Google Drive

PreviousCreating PolicyNextPosture Management Events Page

Last updated 8 months ago

Was this helpful?

This document explains what admins and end-users can do once a policy is violated.

Admin Notification and Remediation

When end-users violate a policy, the Nightfall admin is notified about the incident. The notification channel used to notify the Nightfall admin depends on the settings configured in the section. If you have not enabled any notification channels in the Admin alerting section, Nightfall admins are not notified.

If you have enabled the email notification in the Admin alerts section, Nightfall admins receive an email. The email is as shown in the following image.

The Email consists of the following data.

  • Event: The event that caused the violation. For Google Drive, the event is always a download of assets.

  • Actor: The Email ID of the user who downloaded the file.

  • When: The date and time when the email was downloaded.

  • Where: The name of the file that was downloaded.

  • Policies Violated: The name of the policy that was violated.

  • Violation Dashboard: The link to the Events screen to view the violation in detail.

  • Actions: The list of actions that the Nightfall admin can take.

Also, a Slack message is sent if you have enabled the Slack alerts for the Nightfall admin. The Slack message looks as shown in the following image.

End-User Notification and Remediation

If you have configured the Email notification for end-users and enabled the end-user remediation, end-users can take remediation actions from the Email itself.

The end-user Email for adding external users violation is shown in the following image.

The end-user Email for adding Changing Share settings violation is shown in the following image.

If you have configured Slack notifications for end-user and enabled end-user remediation, end-users can view the Slack message.

Managing Violations in Nightfall

Nightfall admins can manage violations from within the Nightfall console. The Posture Management Events page in Nightfall lists all the violations under the Posture tab. End-users can get a detailed view of each Posture violation recorded. To learn more about Posture Management Events page, refer to the Posture Management Events Page document.

End-users receive notifications and remediation actions if the Nightfall admin has enabled these settings. The notifications are based on the settings configured in the section. The end-user remediation actions are based on the settings configured in the section.

Automation
End-User Remediation
Admin Alerting